General

  • Target

    Hydrogen_Executor_V3.exe

  • Size

    190KB

  • MD5

    1399f90b10f8ba4e8894844b637c3674

  • SHA1

    c4b55243750434a4ffc5e654c9301bed89c53a9b

  • SHA256

    9ee7472a507976b837fa9b21959b942b1a488f28a6746f0540b6936b938c16d9

  • SHA512

    729f4e45ac49780c79569e577c2b6c9e76908dcf6c66b7b35aae5e9055ec3242387510dbae671617e9c56dc5fab68220061a7466e12eeccc4ad41ed9d0b4a068

  • SSDEEP

    1536:cc1ZubZumexWTkF7ELjxNYK/HqJLG+Pr:R1ZubfecTkF7EHrfqPr

Score
10/10

Malware Config

Extracted

Family

mercurialgrabber

C2

https://discord.com/api/webhooks/1239296125064974418/PUgXB5FXV6rG9VgXFqZRFI0mCViixOJ8UuqFBuJflxFjy8K_1Bnlcsm6oiqDYfXj8zlI

Signatures

  • Mercurialgrabber family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Hydrogen_Executor_V3.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections