Malicious
Malicious

dc1244712bae6d520128c5e70ce61ea9

Share on LinkedIn
Print
PE Executable
MD5: dc1244712bae6d520128c5e70ce61ea9
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 dc1244712bae6d520128c5e70ce61ea9
Sha1 6fb87596fe6952db8d69dde9b709c819faf5bd67
Sha256 2a0bc1efd509f72273c3f9e3143a3f108edfa4d33dc9c1ba4a86ce362deea86a
Sha384 5e4113c91a9e164391c5c3f258b2c90f3d64973c8a5cd6e5266752d54c91f3c9c50732a10382d2554656ad2144a215ed
Sha512 684c389cd3e857dad8a7174cec692114c7d84715bd240c443ce4bcd19a4a31bddc742595809cee512792030345e600ded2be0fba203582b3706b64531aa8ac38
SSDeep 768:UuYHKTsufqG9vSLjWUvlPRmo2qbZaGMgvgePIdRS8D0bCafLPPyD8cX1jAFZ6BBL:UuYHKTsjMvSX25iidRjobCafjKD1JBbd
TLSH 1E232C043BE9812BF2BE4F74A8F32245857AF6673603D65D1CC451975613FC28A42AFE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) dzRpUnhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature mtVXrLhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts lovehuhuhuhuhuhuhu
Ports 4huhuhuhu
Mutex A9hvhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group lovehuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
qrSJSYOrtyCZf
Full Name
qrSJSYOrtyCZf
EntryPoint
System.Void VSJLOzZrltuBuI.hqSLUdDMny::Main()
Scope Name
qrSJSYOrtyCZf
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
csgo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void VSJLOzZrltuBuI.hqSLUdDMny::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::TydBePXrXcWXggp
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean VSJLOzZrltuBuI.NAvwcyjxTeO::HRFHIRGisAe()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean ZomdStztXBc.EuesMryyEBGgeDU::SdYTIodkquaE()
brtrue IL_0043: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::XQIRpqUbUnhBbR
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::XQIRpqUbUnhBbR
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::CQnSCHDoKLpqx
call System.Void ZomdStztXBc.DmthoxkeZpX::jxAmUkGFDdX()
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::CQnSCHDoKLpqx
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::AxljxPEEzW
call System.Void rnEipxlDPFCly.FvBzoGZzPaxLq::vyWywUVXaCbVfmF()
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::AxljxPEEzW
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
call System.Boolean ZomdStztXBc.KamytlBCUAB::CXSYrFjiCtmBC()
brfalse IL_0089: call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
call System.Void ZomdStztXBc.eiodDVXjukV::DodpSlxRrSIGaj()
call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean iUrMzfFnGFTw.GwGPtxxvRYOPNv::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void iUrMzfFnGFTw.GwGPtxxvRYOPNv::UQxRqShMhFH()
call System.Void iUrMzfFnGFTw.GwGPtxxvRYOPNv::cErpWlKAZwE()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
qrSJSYOrtyCZf
Full Name
qrSJSYOrtyCZf
EntryPoint
System.Void VSJLOzZrltuBuI.hqSLUdDMny::Main()
Scope Name
qrSJSYOrtyCZf
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
csgo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void VSJLOzZrltuBuI.hqSLUdDMny::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::TydBePXrXcWXggp
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean VSJLOzZrltuBuI.NAvwcyjxTeO::HRFHIRGisAe()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean ZomdStztXBc.EuesMryyEBGgeDU::SdYTIodkquaE()
brtrue IL_0043: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::XQIRpqUbUnhBbR
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::XQIRpqUbUnhBbR
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::CQnSCHDoKLpqx
call System.Void ZomdStztXBc.DmthoxkeZpX::jxAmUkGFDdX()
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::CQnSCHDoKLpqx
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::AxljxPEEzW
call System.Void rnEipxlDPFCly.FvBzoGZzPaxLq::vyWywUVXaCbVfmF()
ldsfld System.String VSJLOzZrltuBuI.NAvwcyjxTeO::AxljxPEEzW
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
call System.Boolean ZomdStztXBc.KamytlBCUAB::CXSYrFjiCtmBC()
brfalse IL_0089: call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
call System.Void ZomdStztXBc.eiodDVXjukV::DodpSlxRrSIGaj()
call System.Void ZomdStztXBc.KamytlBCUAB::jrYuOxIAHodelV()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean iUrMzfFnGFTw.GwGPtxxvRYOPNv::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void iUrMzfFnGFTw.GwGPtxxvRYOPNv::UQxRqShMhFH()
call System.Void iUrMzfFnGFTw.GwGPtxxvRYOPNv::cErpWlKAZwE()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
dzRpUnhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
lovehuhuhuhuhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
A9hvhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙