Suspicious
Suspect

893687a58445ef269924192f6e0d6ddd

PE Executable
MD5: 893687a58445ef269924192f6e0d6ddd
Size: 756.74 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 893687a58445ef269924192f6e0d6ddd
Sha1 6aa01e8547bec062ea80888077ff97d33883286d
Sha256 c0676910f1362864201df2da6fc69db6b679c8ba7fc0f66a2dc47c2236142bce
Sha384 19f410a7870f7125526617bf737654b9599ab9c8017c4b997f48c4d972b8feb98a6cff183c0af1e0364acbf9aa281515
Sha512 2a63ac3648ac5ce2467e0afb29f5278bc7494914f35428bd7c9d5a111252c211f02d42d94e2c25c8f943280a88dc367579aae3f28b36f9ecc544620e378dab28
SSDeep 12288:Kjj6ACHqDkVdgByrqASPIDv5fj85wd4DwgxtnN4RKEQlBXAapI0:ImAjofqjCv5tvOtC+LI0
TLSH E8F4DF146D6DAB1DECA963F1C870F27403B16DA96422E70A4DE93CE77B23B0C1526763
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
pTKi
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
KyYp.exe
Full Name
KyYp.exe
EntryPoint
System.Void SoftwareMercado.Program::Main()
Scope Name
KyYp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KyYp
Assembly Version
3.7.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
573
Main Method
System.Void SoftwareMercado.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SoftwareMercado.frmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
pTKi
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
893687a58445ef269924192f6e0d6ddd
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙