Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: dbdfd9ab774d8fa5a56718b1fae7bc95
Size: 279.04 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dbdfd9ab774d8fa5a56718b1fae7bc95
Sha1 df4c5c42e6b8d3c7324a34a2b017f362d9213558
Sha256 604c471648621880aeceac0534190b14e8c3ea05d4bc5bb95a8e777dd82e65aa
Sha384 67bffe054c88a26462519fe997c30d8bc540d7ae5b45b2ee5b62d2e946c88ab0ba74f10b6b9620e21e58f2e06f4f1848
Sha512 d3478dd32f89105cd62997f539961bb69a7eb08ca614f9185c29a32cb96f3dbc87638fea6eb09717ad67696d5aab1a39373aaddf0fd0c057ea6787346d7a31c8
SSDeep 3072:ne/3hGz8Su8ucwsy7vf7Qy63S9scCh4slxWsr7i9W3WWsZHpV0iukwEEfzqygF/S:n6xqucZy7vf8f3oMRxb/3W1Hp91Gq
TLSH 83546B6136A2CD7AD68020FF5C9DAABE1F1B889B6F8496E3B4945C4D5CB03D74231F41
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.00cfg
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet hahuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙