Suspicious
Suspect

68cd9bd4fc5d28a1f10af6b9a4e8544a

PE Executable
MD5: 68cd9bd4fc5d28a1f10af6b9a4e8544a
Size: 12.18 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 68cd9bd4fc5d28a1f10af6b9a4e8544a
Sha1 d63b0fc549b0070267884169c9591cbc7e349775
Sha256 9c8b32d0222ad5e686a00a393bde88476ec005ef06ce4315a18f8738287e49ae
Sha384 3e9662f1b5b6945ab8c8b7f774bdb600ab4e2be69c64cb2ab7e17a15edf0d6e499b7772ccff96239d08873ee569e698f
Sha512 2b8d0b17e5bec22a075554a3b3ea931ab716a00e5f9f83284532f94739180b45c8186bb8b49bbb7efdd3b5fd5a3e94a8de10d7b735d14530af3ef22f861e6748
SSDeep 196608:IuydQ9uLiFuc8FeC+HhrfOQRin96tCYreMahY/vEsCkenWI2WR2DVayWvlNxFEm:1ydQbNCyhjm6tC+HE2e7O2lNxFE
TLSH B6C63347B1D69E1ACEF53BB348E6D23407BD2C8BA963D59767DCB9973C0235D6880202
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
tf.uX.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RescueStation.Properties.Resources.resources
Apollo
[NBF]root.Data
kLUG
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
WNyp.exe
Full Name
WNyp.exe
EntryPoint
System.Void mv.M4::sP()
Scope Name
WNyp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WNyp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
329
Main Method
System.Void mv.M4::sP()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0017: call System.Void OJ0.qJg::skl()
call System.Void OJ0.qJg::skl()
br IL_0023: nop
nop <null>
ret <null>
nop <null>
newobj System.Void tf.uX::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
tf.uX.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RescueStation.Properties.Resources.resources
Apollo
[NBF]root.Data
kLUG
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙