Suspicious
Suspect

4a2a776bed68a7ac1fa2b07a8f6cd7ae

PE Executable
MD5: 4a2a776bed68a7ac1fa2b07a8f6cd7ae
Size: 12.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4a2a776bed68a7ac1fa2b07a8f6cd7ae
Sha1 fba32ab156d80533bd5941690df956492c40af8e
Sha256 3148ffe9917d2aa33cf61f1f2858ae35d659fedcdc15a2dead0cb6e4792579cd
Sha384 8d565ec452b9631a916dde8966ddad3e5aac4b8c66b75f5a19f7b0a84ac223f6631736fa60c7d6f05160e931c8586661
Sha512 dead3bddd345a2ae6b6576744518e20be1453039b80fec9fe3ff3a9ad609b68dd2267ff9007509a8d829f44f117706531170d7356bd5c8faddfed5d5b3aadf6c
SSDeep 196608:a7Aj+6Y+1fsKPuMMU7U7gHttex1UDOxlgQt6ZqXJTKQ8ayNH7oXiR6KpE+:d+12jRbteD2Oxl6ZqXNKPayNoQ66E
TLSH 2CC63328DAFE8E26EDF197710C66C23207B19D8F9250E3085AE8DDC3BD2D5B59645233
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VgUn
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ncXc.exe
Full Name
ncXc.exe
EntryPoint
System.Void Seismograph.Program::Main()
Scope Name
ncXc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ncXc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void Seismograph.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Seismograph.frmMonitor::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VgUn
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙