Malicious
PE Executable
MD5: dcf43d26d9539424c87e7c1658f702d9
Size: 65.54 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | dcf43d26d9539424c87e7c1658f702d9 |
| Sha1 | a72565e064bb2277fb0413614890926325d7380d |
| Sha256 | f70d9ba4d86e23fcad6e2173cf17c08d31c4a873553b8516acc2fe25249cf8ee |
| Sha384 | ae335e8c90b603a9ef9c4069c5c993999698b00427bd4a619774ef1533842b472c32cfd82c0fccca88a7438c3f49bf76 |
| Sha512 | b1c64307550b6ef7e55a9206dc81ed21383a7891d885e55e9ed887e8a9c36914f38fcc8eaecd70cd062ae35b7dc702a918a07e80f943b1cac1e9c010f3107f60 |
| SSDeep | 768:ym0vnfEXf78awC8A+XUptkviZd9s/rCm1+T4uStGHmDbDcph0oXYl2KSu8dpqKYC:aEXiSKviZdAZx0UbKh9wAu8dpqKmY7 |
| TLSH | 0F536D003B98C965E2AE46B8BCF355004AB5D6772112DA5E3CC810DB6B5FFC646127FE |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Config. Field | Value |
|---|---|
| Key (AES_256) | QXIyQWhuhuhuhuhuhuhuhuhuhuhu |
| Pastebin | -huhuhuhu |
| Certificate | MIICKThuhuhuhuhuhuhuhuhuhuhu |
| ServerSignature | Hr87hYhuhuhuhuhuhuhuhuhuhuhu |
| Install | fhuhuhuhu |
| BDOS | fhuhuhuhu |
| Anti-VM | fhuhuhuhu |
| Install-Folder | %Aphuhuhuhu |
| Hosts | anarchhuhuhuhuhuhuhu |
| Ports | 1huhuhuhu |
| Delay | 1huhuhuhu |
| Group | Dehuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Module Name | Infected_RREA.exe |
| Full Name | Infected_RREA.exe |
| EntryPoint | System.Void Client.Program::Main() |
| Scope Name | Infected_RREA.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Infected_RREA |
| Assembly Version | 3.6.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 163 |
| Main Method | System.Void Client.Program::Main() |
| Main IL Instruction Count | 77 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_0f343b09.bin (1024 bytes) |
| Module Name | Infected_RREA.exe |
| Full Name | Infected_RREA.exe |
| EntryPoint | System.Void Client.Program::Main() |
| Scope Name | Infected_RREA.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Infected_RREA |
| Assembly Version | 3.6.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 163 |
| Main Method | System.Void Client.Program::Main() |
| Main IL Instruction Count | 77 |
| Main IL | |
Key (AES_256)
MUTEXmalicious
QXIyQWhuhuhuhuhuhuhuhuhuhuhu
CnC
CNCmalicious
anarchhuhuhuhuhuhuhu
Ports
PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential