Suspicious
Suspect

PE Executable
MD5: af80a1fc2dd0ad6eb4c65675e08caa0c
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 af80a1fc2dd0ad6eb4c65675e08caa0c
Sha1 ab67cc33c035343e5459aa4e8f923302e79c3b7d
Sha256 2acbd38d75a998bc663dc7f1ba6ccccf87d9724557b52b2966250cba1c70286b
Sha384 61fcc5aea24460e786d5ad5713241cc5b942d82b995a7061e9fda8b4af7f3fd659fd302a4563a7b9cdeba9d78c47bcaf
Sha512 7e52f8b923a059ba8aa9410cf102e12f0eb4ef9f24563e5ee1fa1d7f803d11b3dbc6869c00cb9b5b1c6a33e51bebfee032c34527d9a4c246fb0d3c337e1eb442
SSDeep 24576:TedYU4/vjI4wrJF0fWoNWe1kQIZxzF1Et4CXHleFiXrX:Tedh0I4wrb0ftIZuH
TLSH 1D45029C7215F9EFC897D1714AA4EE70A6242C6AD316810389F71CDFB90EE57EE140E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
Yloj
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
dDck.exe
Full Name
dDck.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
dDck.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dDck
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‍‌‍‮‪​‏‎‬​‬‪‮‭‌‪‫‮‏​‪‏‭‏‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‬‏‍‪​‍‏‬‮‮‭‌‎‮‏‌‫‮‪‏‬‫‎‌‏‌‎‫‍‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‭‬‍‌‬‫‎‫‮‌‏‌‭‪‮‭‪‮‍‎‪‬‎‪‏‎‮(System.Windows.Forms.Form)
ret <null>
Module Name
dDck.exe
Full Name
dDck.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
dDck.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dDck
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‍‌‍‮‪​‏‎‬​‬‪‮‭‌‪‫‮‏​‪‏‭‏‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‬‏‍‪​‍‏‬‮‮‭‌‎‮‏‌‫‮‪‏‬‫‎‌‏‌‎‫‍‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‭‬‍‌‬‫‎‫‮‌‏‌‭‪‮‭‪‮‍‎‪‬‎‪‏‎‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
Yloj
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙