Suspicious
Suspect

68cd9bd4fc5d28a1f10af6b9a4e8544a

Share on LinkedIn
Print
PE Executable
MD5: 68cd9bd4fc5d28a1f10af6b9a4e8544a
Size: 12.18 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 68cd9bd4fc5d28a1f10af6b9a4e8544a
Sha1 d63b0fc549b0070267884169c9591cbc7e349775
Sha256 9c8b32d0222ad5e686a00a393bde88476ec005ef06ce4315a18f8738287e49ae
Sha384 3e9662f1b5b6945ab8c8b7f774bdb600ab4e2be69c64cb2ab7e17a15edf0d6e499b7772ccff96239d08873ee569e698f
Sha512 2b8d0b17e5bec22a075554a3b3ea931ab716a00e5f9f83284532f94739180b45c8186bb8b49bbb7efdd3b5fd5a3e94a8de10d7b735d14530af3ef22f861e6748
SSDeep 196608:IuydQ9uLiFuc8FeC+HhrfOQRin96tCYreMahY/vEsCkenWI2WR2DVayWvlNxFEm:1ydQbNCyhjm6tC+HE2e7O2lNxFE
TLSH B6C63347B1D69E1ACEF53BB348E6D23407BD2C8BA963D59767DCB9973C0235D6880202
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
tf.uX.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RescueStation.Properties.Resources.resources
Apollo
[NBF]root.Data
kLUG
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
WNyp.exe
Full Name
WNyp.exe
EntryPoint
System.Void mv.M4::sP()
Scope Name
WNyp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WNyp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
329
Main Method
System.Void mv.M4::sP()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0017: call System.Void OJ0.qJg::skl()
call System.Void OJ0.qJg::skl()
br IL_0023: nop
nop <null>
ret <null>
nop <null>
newobj System.Void tf.uX::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
An error has occurred. This application may no longer respond until reloaded. Reload 🗙