Suspicious
Suspect

861e3af88bf1bcac9caf72bf16fa02b5

PE Executable
MD5: 861e3af88bf1bcac9caf72bf16fa02b5
Size: 24.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 861e3af88bf1bcac9caf72bf16fa02b5
Sha1 d0e4300ef05b840b0f36e198eb634b54a917761d
Sha256 ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f
Sha384 b0ec63275085e3a6903c1e6fbe378d1605bdc61cc39c6f8597a7ea7cdb4e35aadffe7828fd393c6f14e6205c9948b61c
Sha512 0eb28e34b41fe76f9fc8cf49c0f07e69ecbb96070ea19c4f8b821738b30e18a7a64c649262c0a219219758e26bf7adbaa13880df90cbdd5c251986ee87b9e9a2
SSDeep 196608:a7Aj+6Y+1fsKPuMMU7U7gHttex1UDOxlgQt6ZqXJTKQ8ayNH7oXiR6KpE+:d+12jRbteD2Oxl6ZqXNKPayNoQ66E
TLSH 27373328DAFE8E26EDF197710C66C23207B19D8F9250E3085AE8DDC3BD2D5B59645233
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Overlay_21181abf.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VgUn
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_21181abf.bin (12050944 bytes)
Module Name
ncXc.exe
Full Name
ncXc.exe
EntryPoint
System.Void Seismograph.Program::Main()
Scope Name
ncXc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ncXc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void Seismograph.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Seismograph.frmMonitor::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Overlay_21181abf.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VgUn
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙