Suspect
PE Executable
MD5: 6ca21b5b6fabcc30ee6c1b9ac79e26f2
Size: 870.4 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | 6ca21b5b6fabcc30ee6c1b9ac79e26f2 |
| Sha1 | 63a3719846956a894cb5070022c298f53dcf9afa |
| Sha256 | 2ce0358958dec9420addee948555ce5fd0810e9b6054c6a9d5b472e93501e582 |
| Sha384 | 1fdc0b13073709f34da10a67cc78a5efa135365cd40b3d01ffd632245ff26f06ac7b1ea5a2409614e3cc4b481e58d833 |
| Sha512 | e23d4ab398c4c1d82c813346746e554789ab60e8a85850d037b182598c148ce01c8f267c695d8f21f1b30256311e1efca7bf6a007b87fd0cafcd42bb33a4fbc1 |
| SSDeep | 12288:8wbT2qCKqOZQ8rmCGdYV7gLqBkAI+TOF7uZFAvjv+ztB7Gmmazyzz5SPRYEnb:p2sRQA9GdYV7gLikAVaF7XjCU |
| TLSH | 6805CF9C3254B59EC413CD728974ED70AA207D6AA70BC20395D72E9FB91DA96DF002F3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | nYcn.exe |
| Full Name | nYcn.exe |
| EntryPoint | System.Void EventLogAnalyzer.Program::Main() |
| Scope Name | nYcn.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | nYcn |
| Assembly Version | 3.7.2.4 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 341 |
| Main Method | System.Void EventLogAnalyzer.Program::Main() |
| Main IL Instruction Count | 96 |
| Main IL | |
| Module Name | nYcn.exe |
| Full Name | nYcn.exe |
| EntryPoint | System.Void EventLogAnalyzer.Program::Main() |
| Scope Name | nYcn.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | nYcn |
| Assembly Version | 3.7.2.4 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 341 |
| Main Method | System.Void EventLogAnalyzer.Program::Main() |
| Main IL Instruction Count | 96 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.