Suspicious
Suspect

3d639a627186e77730ff2d1294df49a3

PE Executable
MD5: 3d639a627186e77730ff2d1294df49a3
Size: 681.47 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3d639a627186e77730ff2d1294df49a3
Sha1 dd971d09f94dbd77735a07fc297dd2836fd94616
Sha256 89f6c08fa045d14eb73a0992145a724bc34d531d7af3dcc4901a1b7c7833aede
Sha384 1dfb3bcc54c6d0e7d44ab50c85ad827599ef9de5e7fc6382f3e104bc338adde2f6a1a3edf78fc3ef7f9a765169092e43
Sha512 958714417be43fa8e1e0ccd1bc4e8a09187192ee8ce219d394fe89a09273aef4384387a777ae609500812821e3d40206adb86cf1fc50451358422f153dbecc0b
SSDeep 3072:sAf07/cWVdNFWe3GthMEIO3jmbaFaexjbzyJlPgPg:+5Vdn7WthLDxjbQs
TLSH 72E4BD0E83954667ED206972AD6E7B41C2A51A3E7C63F7B9FF183243B9213C4453363A
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Overlay_816df6f6.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LDyKw.g.resources
AutosavePaint.Print.resources
AutosavePaint.Properties.Resources.resources
NGJiz
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_816df6f6.bin (512000 bytes)
Module Name
LDyKw.exe
Full Name
LDyKw.exe
EntryPoint
System.Void AutosavePaint.App::Main()
Scope Name
LDyKw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LDyKw
Assembly Version
26.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
33
Main Method
System.Void AutosavePaint.App::Main()
Main IL Instruction Count
10
Main IL
nop <null>
newobj System.Void AutosavePaint.App::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Void AutosavePaint.App::InitializeComponent()
nop <null>
ldloc.0 <null>
callvirt System.Int32 System.Windows.Application::Run()
pop <null>
ret <null>
Module Name
LDyKw.exe
Full Name
LDyKw.exe
EntryPoint
System.Void AutosavePaint.App::Main()
Scope Name
LDyKw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LDyKw
Assembly Version
26.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
33
Main Method
System.Void AutosavePaint.App::Main()
Main IL Instruction Count
10
Main IL
nop <null>
newobj System.Void AutosavePaint.App::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Void AutosavePaint.App::InitializeComponent()
nop <null>
ldloc.0 <null>
callvirt System.Int32 System.Windows.Application::Run()
pop <null>
ret <null>
Overlay_816df6f6.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LDyKw.g.resources
AutosavePaint.Print.resources
AutosavePaint.Properties.Resources.resources
NGJiz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙