Suspicious
Suspect

ddeb98aef74364d5068836f404613d92

PE Executable
MD5: ddeb98aef74364d5068836f404613d92
Size: 2.99 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ddeb98aef74364d5068836f404613d92
Sha1 6c672941ca5610ea2b50863fdfdac6180645986c
Sha256 60977eca0c78ae08cb9a2ea3a52ce0f8b49f3df7522b5fb5ee8eeb1a46510f56
Sha384 0cf2519833535570596b39458bd502bff7f8b036eaa00de508b676945e6d5186a6b7bd9be89ca961829d52a0aa4b5da9
Sha512 f82e8a077fa66fa65f4cb450da2bb92884aac4087c7b1abf4cc7629620cc6fd99f30a0970db6dc2d411cbd11ddfbf89f10f4c87d3cc659e0f359fc59b2d013e0
SSDeep 49152:3YNnGDNaciFItbKJZ6HlTbFav4l+ZzEUINav8aOuMBNn4VBj6Og6n/QwS2Ke:oJUNdiFItAZ6HlHFpUJvVOuy4V5a6/QG
TLSH 1FD52398661AE913CB5423344AB2F2744278AFDEB901D22B5FD9BEFB7931F410C405A7
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChimneySweep.DachForm.resources
ChimneySweep.Properties.Resources.resources
Giga
[NBF]root.Data
cLcZ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YSNH.exe
Full Name
YSNH.exe
EntryPoint
System.Void ChimneySweep.Program::Main()
Scope Name
YSNH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YSNH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
181
Main Method
System.Void ChimneySweep.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldstr !!!!!!!!!!!!!!!!!!!634C635A!!!!!!!!!!!!!!!!!!!636269!!!!!!!!!!!!!!!!!!!admin!!!!!!!!!!!!!!!!!!!123456
ldstr 
newobj System.Void ChimneySweep.DachForm::.ctor(System.String,System.String)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChimneySweep.DachForm.resources
ChimneySweep.Properties.Resources.resources
Giga
[NBF]root.Data
cLcZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙