Suspicious
Suspect

6ff3cc67b35a5caed0468ea9352506e9

PE Executable
MD5: 6ff3cc67b35a5caed0468ea9352506e9
Size: 772.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6ff3cc67b35a5caed0468ea9352506e9
Sha1 e1de54b8f46e5c4fa38052f0cf5891e7d35549a9
Sha256 57f5d6a0f4ba2b5db7c32af655a63a62b82e83f8bc03650f953eed6a6f0e1fa2
Sha384 ae1265290fb598681443fcc2e4512c3ed78a401c0d3e6689eaa5fb96caec445667354da7863d04e6d0f57faec4859c7d
Sha512 20142dbad5fc1bdd642ee64dee3cd9742d5c7f81a8d801f152850f64be1bf8e1bb6b2b575bc578ca4b89096cc6b9ebf19615018690e65bbe79140708cb2f66fa
SSDeep 12288:Ruo+0HjJ35LZ6LxWq76MSlNl5tuinL5CiPAwq4r/QGmuQv4lRl4e:Io+qz6LoqIlNHtu0VfP1q4r/QNv4Ll
TLSH 16F412687726FE52C9AD4B750A77E33413A59E5DE111C327CBEE9DEF3C20245AC08682
PeID
UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
VirtualMachine26.Abou.resources
VirtualMachine26.Me.resources
Apollo
[NBF]root.Data
VirtualMachine26.Properties.Resources.resources
WUqh
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ILQbnbWWjl\src\obj\Debug\NvRO.pdb
Module Name
NvRO.exe
Full Name
NvRO.exe
EntryPoint
System.Void VirtualMachine26.Program::Main()
Scope Name
NvRO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NvRO
Assembly Version
26.1.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
171
Main Method
System.Void VirtualMachine26.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void VirtualMachine26.DebuggerUI::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
VirtualMachine26.Abou.resources
VirtualMachine26.Me.resources
Apollo
[NBF]root.Data
VirtualMachine26.Properties.Resources.resources
WUqh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙