Suspicious
Suspect

660dac63c924b53c5909e53146c94ead

PE Executable
MD5: 660dac63c924b53c5909e53146c94ead
Size: 572.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 660dac63c924b53c5909e53146c94ead
Sha1 de5b69564eca9ab96fde4e46202236723ac54e19
Sha256 4bfe304587633df9d042ede596f957bace69740c37bc40a6635cabe101802c65
Sha384 c10782ec165e765711f250b6c3c1e0ee7e2c28bd7acbaee9f8fc0f9f237e08668fd4c16464adff628a05f0a3179701be
Sha512 c187100c9e26e1751d9eb388a57549004f8ad81d6162d2a8f6c903e97f5e1303d85dda99afbc3ae2963c0ce9aa803ad29e26d60afadda5cf2e0ceff00d7f9504
SSDeep 12288:AG5aW8X5x8QSZcC90+/TFH/YW3aJPdJP5uXxDT0Hvo:tZb/TFgWqJVJBuhDQw
TLSH CEC4E11C73AADB02D4B607F55A71F27023FA7D4E9920D21B8FE5BDE73821B052948693
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CranberryBog.Properties.Resources.resources
GUI
[NBF]root.Data
OACL
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
VYXi.exe
Full Name
VYXi.exe
EntryPoint
System.Void CranberryBog.Program::Main()
Scope Name
VYXi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VYXi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
468
Main Method
System.Void CranberryBog.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CranberryBog.Formlar.BataklikForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CranberryBog.Properties.Resources.resources
GUI
[NBF]root.Data
OACL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙