Suspicious
Suspect

69cf5802bf20d0da0f3ab5ef3a16f7be

PE Executable
MD5: 69cf5802bf20d0da0f3ab5ef3a16f7be
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 69cf5802bf20d0da0f3ab5ef3a16f7be
Sha1 3cc04044132af748e653919792bd793ae33ae6c3
Sha256 d02933a070a77192644165fb5b0b681aea168ee1ee8e9012cc9c19a5a9e2fcd2
Sha384 9b423bc06bcd103244ca90b6d2dedca1cb683d4ef6af7575246f9cf53f7aad0c7cfbe79ff5eb9ec5747f0c1fc991dc5b
Sha512 60e2e54fa3743bdb99b4ce5d2a0803aac53795a95d62aa9c610ad2e9c17a8c3fd2be646838f41d15cfb52d3bc4fcce6e75b684aff78da93547899e2a8cf78519
SSDeep 24576:m0YNHMaEsBD+wD2okLe1LMuzv6yjLvZDamVjnfT9HBSI:/YNHMzmD+A2oBlTp0mVj79HBx
TLSH FB3501696A1ADA17C9045B381BB1F27913AC6EDEF900D2069FDDBEFB7876B004D04193
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChimneySweep.DachForm.resources
ChimneySweep.Properties.Resources.resources
Giga
[NBF]root.Data
UJno
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
rcdt.exe
Full Name
rcdt.exe
EntryPoint
System.Void ChimneySweep.Program::Main()
Scope Name
rcdt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rcdt
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
181
Main Method
System.Void ChimneySweep.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldstr !!!!!!!!!!!!!!!!!!!554A6E6F!!!!!!!!!!!!!!!!!!!756368!!!!!!!!!!!!!!!!!!!admin!!!!!!!!!!!!!!!!!!!123456
ldstr 
newobj System.Void ChimneySweep.DachForm::.ctor(System.String,System.String)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
rcdt.exe
Full Name
rcdt.exe
EntryPoint
System.Void ChimneySweep.Program::Main()
Scope Name
rcdt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rcdt
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
181
Main Method
System.Void ChimneySweep.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldstr !!!!!!!!!!!!!!!!!!!554A6E6F!!!!!!!!!!!!!!!!!!!756368!!!!!!!!!!!!!!!!!!!admin!!!!!!!!!!!!!!!!!!!123456
ldstr 
newobj System.Void ChimneySweep.DachForm::.ctor(System.String,System.String)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChimneySweep.DachForm.resources
ChimneySweep.Properties.Resources.resources
Giga
[NBF]root.Data
UJno
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙