Malicious
Malicious

PE Executable
MD5: e51acd6dd40d6a222c5d831fe5eb7898
Size: 48.13 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e51acd6dd40d6a222c5d831fe5eb7898
Sha1 20d95716bd363f82e3cc28dbc228022a43bb2aa2
Sha256 7342988689d731203018dcda74937b54d614323a1dc43cf85d3239b9f62c1ae4
Sha384 0b99dce97e5db0c84be585e0794ed35e4540b0b1ffa5275d36156328c4f2421ba7c543d96f6c76d2cc57fddcd430530c
Sha512 792f82d7c48ea34d95eed22da1f6e4539646fb13e7034135917c14c273efd01ea92a549b1f06a5ca6222fd198a2c1a47d707bbe0281b70178241b392f8ea66ed
SSDeep 768:Kue+pTjVOoYWUiMA6Omo2q4u4Jr3NJ8lVVOPINzjbwg53iS0/fepAdWg7BvwEP3d:Kue+pTjAXY2m4JRmf3N3b35Sj/T1BTd9
TLSH C3233B003BE9812BF2BF5F789DF25145867EF5633603E54E1C84029B5623FC59A826FA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) VkNDS0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature lfIT7rhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File VSDCCihuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts www.ubhuhuhuhuhuhuhuhuhuhuhu
Ports 80,443huhuhuhuhuhuhuhuhuhuhu
Mutex VSDC_Chuhuhuhuhuhuhuhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group AtlasGhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
VSDCCitadelNetwork.exe
Full Name
VSDCCitadelNetwork.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
VSDCCitadelNetwork.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VSDCCitadelNetwork
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Module Name
VSDCCitadelNetwork.exe
Full Name
VSDCCitadelNetwork.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
VSDCCitadelNetwork.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VSDCCitadelNetwork
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
VkNDS0huhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
www.uhuhuhuhuhuhuhu
CnC CNCmalicious
ubdohuhuhuhuhuhuhu
CnC CNCmalicious
biglobhuhuhuhuhuhuhu
CnC CNCmalicious
www.bihuhuhuhuhuhuhu
CnC CNCmalicious
www.huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
5huhuhuhu
Ports PORTmalicious
6huhuhuhu
Ports PORTmalicious
6huhuhuhu
Ports PORTmalicious
6huhuhuhu
Ports PORTmalicious
7huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
VSDC_Chuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) VkNDS0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature lfIT7rhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File VSDCCihuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts www.ubhuhuhuhuhuhuhuhuhuhuhu
Ports 80,443huhuhuhuhuhuhuhuhuhuhu
Mutex VSDC_Chuhuhuhuhuhuhuhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group AtlasGhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
VkNDS0huhuhuhuhuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
CnC CNCmalicious
www.uhuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
CnC CNCmalicious
ubdohuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
CnC CNCmalicious
biglobhuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
CnC CNCmalicious
www.bihuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
CnC CNCmalicious
www.huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
8huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
4huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
4huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
4huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
5huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
6huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
6huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
6huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
7huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
8huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
8huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Ports PORTmalicious
8huhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Mutex MUTEXmalicious
VSDC_Chuhuhuhuhuhuhuhuhuhuhu
e51acd6dd40d6a222c5d831fe5eb7898
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙