Malicious
Malicious

f6e579baf5ab4f957f5da8ed544823f7

PE Executable
MD5: f6e579baf5ab4f957f5da8ed544823f7
Size: 24.06 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f6e579baf5ab4f957f5da8ed544823f7
Sha1 d1f43161309f6a6f2f7655e4511919160fe1f8e2
Sha256 531cd87122624a10bdee2c376119d225dff9797ff7b26ccb30303868d6afcc3d
Sha384 0e7294199a6df10f0186bdcbad73ba1fc57b5336c51c4274af00599dd1e405792900ae3119e74145353feb14a2876851
Sha512 d8e5f691a57289fc19d92b1dfcd3f28c5e1b859ba649e47ddb0ef13e0bb83724dd33d9ac7accf882632155aab297cdc5a0b5967270066b53ae1470eb048a0688
SSDeep 384:C8zmicUDPiJUQrlRGSHCYlbY6ZgvSMBTtxmRvR6JZlbw8hqIusZzZG5x:CEpD2btHxRpcnurD
TLSH E7B22A4E3FA98956C4BC17748AA5965003B491470423FE2FCDC464CBAFB3AD92D4CAF9
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
victim_name [VN] Lahuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] Applichuhuhuhuhuhuhu
directory [DR] AllUshuhuhuhuhuhuhu
reg_key [RG] 5f3448huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] tissuehuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Thuhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
tissuehuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
victim_name [VN] Lahuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] Applichuhuhuhuhuhuhu
directory [DR] AllUshuhuhuhuhuhuhu
reg_key [RG] 5f3448huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] tissuehuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Thuhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
tissuehuhuhuhuhuhuhu
f6e579baf5ab4f957f5da8ed544823f7
Port PORTmalicious
1huhuhuhu
f6e579baf5ab4f957f5da8ed544823f7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙