Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: e17d0e0420e26a6911435ee2fc9bd881
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 e17d0e0420e26a6911435ee2fc9bd881
Sha1 2378a5c6efc3c43a3c6d3f453e4a02ef109e9761
Sha256 9b671e6219a487cfff8202a1372cf92229eb9c372cbf09d6f0822d441a703aca
Sha384 d08e905aaad40462f470a40f9f2cbc375fc0067945f38a79e3a31872a424c2b94428dfa71c6319ba5baf217893fc15d8
Sha512 f6180c09051574291c375bc018f6c7b17fe922e36cc5b3329066cfe4c2634cf0b8789eb3020de81a6f0c6594a1eb624bd99b89fb3027aa286014aad34b11e6a6
SSDeep 768:fu/gbEcT8A03OWU8hhQmo2q90o0G5iF8hjKPI2KG9anLV0b/7fK5h5gjgLaimVM9:fu/gIcT8XG25Cv2KCaLib/bIhKsmimet
TLSH 59232C0037F9822BF27E4F74ACF26146867AF5677603D54A1CC442D74A13FC69A42AFA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) b3Ywc0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature se7HuUhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File googlehuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts megaslhuhuhuhuhuhuhuhuhuhuhu
Ports 22,80,huhuhuhuhuhuhuhuhuhuhu
Mutex xLNPhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
qoeycvOVRuTrHe
Full Name
qoeycvOVRuTrHe
EntryPoint
System.Void hguqfzSHSeE.nxeCVopmPXEY::Main()
Scope Name
qoeycvOVRuTrHe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
noityeubatdau
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void hguqfzSHSeE.nxeCVopmPXEY::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::CHYqjJvEYkAkZ
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean hguqfzSHSeE.RoURqvOIntmaFjp::cPcOElKVxS()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean oXtqYmIzpVqnuG.PLLsjVNrzxD::mZZyBdClxsLAr()
brtrue IL_0043: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::LdjAEdXcDEhNu
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::LdjAEdXcDEhNu
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::VbempdhXEjy
call System.Void oXtqYmIzpVqnuG.BucBxBounEytXOf::TVDJtislfahyi()
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::VbempdhXEjy
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::JSarCNZuxKAb
call System.Void tqFshnGSuu.JTMeTsAGhrXz::XVggShUrtrUorM()
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::JSarCNZuxKAb
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
call System.Boolean oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::GKjBoKMiRDoQp()
brfalse IL_0089: call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
call System.Void oXtqYmIzpVqnuG.chgGECddFZopC::RXJKyOHxKqp()
call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean oraDgxFEonGnI.zJCbLzozvKow::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void oraDgxFEonGnI.zJCbLzozvKow::ynzpRdOZRGxUGr()
call System.Void oraDgxFEonGnI.zJCbLzozvKow::RFhbpoIQSxV()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Module Name
qoeycvOVRuTrHe
Full Name
qoeycvOVRuTrHe
EntryPoint
System.Void hguqfzSHSeE.nxeCVopmPXEY::Main()
Scope Name
qoeycvOVRuTrHe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
noityeubatdau
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void hguqfzSHSeE.nxeCVopmPXEY::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::CHYqjJvEYkAkZ
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean hguqfzSHSeE.RoURqvOIntmaFjp::cPcOElKVxS()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean oXtqYmIzpVqnuG.PLLsjVNrzxD::mZZyBdClxsLAr()
brtrue IL_0043: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::LdjAEdXcDEhNu
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::LdjAEdXcDEhNu
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::VbempdhXEjy
call System.Void oXtqYmIzpVqnuG.BucBxBounEytXOf::TVDJtislfahyi()
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::VbempdhXEjy
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::JSarCNZuxKAb
call System.Void tqFshnGSuu.JTMeTsAGhrXz::XVggShUrtrUorM()
ldsfld System.String hguqfzSHSeE.RoURqvOIntmaFjp::JSarCNZuxKAb
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
call System.Boolean oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::GKjBoKMiRDoQp()
brfalse IL_0089: call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
call System.Void oXtqYmIzpVqnuG.chgGECddFZopC::RXJKyOHxKqp()
call System.Void oXtqYmIzpVqnuG.HCVAnvDABkGAoEE::HquelhXUuZXyh()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean oraDgxFEonGnI.zJCbLzozvKow::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void oraDgxFEonGnI.zJCbLzozvKow::ynzpRdOZRGxUGr()
call System.Void oraDgxFEonGnI.zJCbLzozvKow::RFhbpoIQSxV()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
b3Ywc0huhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
megaslhuhuhuhuhuhuhu
CnC CNCmalicious
malwarhuhuhuhuhuhuhuhuhuhuhu
Ports PORTmalicious
2huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
1huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
5huhuhuhu
Ports PORTmalicious
6huhuhuhu
Ports PORTmalicious
7huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
9huhuhuhu
Ports PORTmalicious
9huhuhuhu
Mutex MUTEXmalicious
xLNPhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙