Suspicious
Suspect

9e9b4bc61cebb52620b08b6c13ceee32

PE Executable
MD5: 9e9b4bc61cebb52620b08b6c13ceee32
Size: 1.01 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9e9b4bc61cebb52620b08b6c13ceee32
Sha1 4fae97e7a419a298bf6b9b0651f3cec84898d2c8
Sha256 b393bd767c142e171dd1b2928bae16fff2f63b3d319b2c1acb37129d8d538cc9
Sha384 7bac841bccce6ceb57f70331c31f3af7c90d0ebf1762849b68bb1fdc6db05bb0142899320750ae02768019a531c23e25
Sha512 898d5e87565c4676ad368271dafcffab99fa547071f9afb43a0e6740725ab7dcec5614e3cc7d46cabfe485cb393a65b82411c5f30c1d0ec5cf118c0041ef4027
SSDeep 24576:tO+LXj/Og3zNx0p/2BouN+OhgNjseUaftqO94iF5P1G5nEj2MPC:tO+LzPxxY/2B0aallqZO5PS+P
TLSH 9C2522A46BE98F06C2FA07F04826D23597B57E1CA062D706CFEAECD734657C056943A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VCvZ
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ncpw.exe
Full Name
Ncpw.exe
EntryPoint
System.Void Seismograph.Program::Main()
Scope Name
Ncpw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ncpw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void Seismograph.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Seismograph.frmMonitor::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Ncpw.exe
Full Name
Ncpw.exe
EntryPoint
System.Void Seismograph.Program::Main()
Scope Name
Ncpw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ncpw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void Seismograph.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Seismograph.frmMonitor::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Seismograph.frmMonitor.resources
Seismograph.Properties.Resources.resources
DR
[NBF]root.Data
VCvZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙