Suspicious
Suspect

PE Executable
MD5: dc9677bc2906eaed2c58c3ca2ef69136
Size: 773.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 dc9677bc2906eaed2c58c3ca2ef69136
Sha1 af433e1427966029dc28bfc0ac06defbdb34eb7e
Sha256 2c626ee34d1b7bc2a39778499f5115574b5bdeeac8cb1837f2d5c3cabfc64868
Sha384 6f2c284b91b15b5fe16b15d0278d1cb2851964b719b29f4b9dccb3a0d8efd73613531d4582893ef0d608d4d0ba45645d
Sha512 e6a2801558126b400923bf6db1c7996db80d11a263db1507822c0edcf834e4ca4255906e133cb57d98e15fe9ef38ceeed30780e4b7c26c4d2d439f8a74cec829
SSDeep 12288:BZRtn3UA9GeV4S2PLvI8fXvbCWawuXu1dxVnqnNq9S9hBMLM7+pYpsBzggUr38B:j3UAInBLIoeflXuvzUq9SrBsMC+pScg+
TLSH AAF4E0287288C405C5BE8377A5B2E57103B9BE17F974D3AD0BD9ACEB3AB0B015C45366
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
TCA
[NBF]root.Data
TouHz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
Bvdyh.exe
Full Name
Bvdyh.exe
EntryPoint
System.Void AnalyzeGraphics.Program::Main()
Scope Name
Bvdyh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Bvdyh
Assembly Version
4.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
760
Main Method
System.Void AnalyzeGraphics.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::Application_ThreadException(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::CurrentDomain_UnhandledException(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void AnalyzeGraphics.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0069: ret
stloc.0 <null>
nop <null>
ldstr Critical error during application startup: 
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr Application Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0069: ret
ret <null>
PDB Path PATH
Bvdhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
TCA
[NBF]root.Data
TouHz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
Bvdhuhuhuhu
dc9677bc2906eaed2c58c3ca2ef69136
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙