Suspicious
Suspect

284921b53c84c0e773f1d875af4c10f7

PE Executable
MD5: 284921b53c84c0e773f1d875af4c10f7
Size: 1.16 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 284921b53c84c0e773f1d875af4c10f7
Sha1 a1971cf2f317f8c7c7088199b72a75c084580797
Sha256 6bde014a76cd6cbe025d0f23e790bc89b7ff22b4d39b3f1372bf97dfc4e4b4a4
Sha384 a75e06c4e650530bed664a3533e29aa803de25aaeb5bb5695fde8753a61fd9d28e0f446df2f05b69220936e77a57b956
Sha512 d1dbba4aa2c92b6f38d09d6f09ea180f8bcb842dba111e52e4f9658e37a440734fee5eb53af5dc186319d6db579606d09a836b6b8b6307e929d93fa176769c94
SSDeep 24576:6pBjP/2oSdvLKuql1UpfC03fRuoLSgThSeBEzaAFEb279XynFrFw:67b/2oS9KCpK0PlSteBN80uyn
TLSH D135DF142262CD02D5E25AB4C8E0E2FF06788D87E911F6078DE67D9F743A648FB156CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HydroReservoir.ParentForm.resources
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
QdJf
[NBF]root.Data
[NBF]root.Data-preview.png
HydroReservoir.RelatioForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
VVnX.exe
Full Name
VVnX.exe
EntryPoint
System.Void HydroReservoir.Program::Main()
Scope Name
VVnX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VVnX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void HydroReservoir.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HydroReservoir.ParentForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
VVnX.exe
Full Name
VVnX.exe
EntryPoint
System.Void HydroReservoir.Program::Main()
Scope Name
VVnX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VVnX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void HydroReservoir.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HydroReservoir.ParentForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HydroReservoir.ParentForm.resources
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
QdJf
[NBF]root.Data
[NBF]root.Data-preview.png
HydroReservoir.RelatioForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙