Suspicious
Suspect

fcc62dc776526cc0f9e6c7edafcb2594

PE Executable
MD5: fcc62dc776526cc0f9e6c7edafcb2594
Size: 849.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fcc62dc776526cc0f9e6c7edafcb2594
Sha1 93cc60755577b561a9daefad6098a388cb2be34b
Sha256 fdc4f6f01f98760794e04c00c6d9f2cd2332cbd7569c87663302c4deeb8a2e47
Sha384 075a2e155dbc9a9cfc0109563618f4178d284f935ab7c4ee9a519ec31e1aed9550400b4522b80cf6fe9507f6b17d5f39
Sha512 16e05244be7ad107bff1dd4ab9893d6b46295dd585ca88c10c0f72e542e90aa04bad4ef7333035fb54685dc4dd1c927e302816c7a3f007f14a7c53ed8ca8da4d
SSDeep 24576:p90ZPWGQ5pIQvFpgmq7vlAcEAJXD/V2jP7o0g:70hW2Qv0mfvAFD/kjPC
TLSH 620512C523A7EA06C5666FF44970C33657B17E49B525E3078EEABCEB783974028412E3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QueryFormat.Forms.MainForm.resources
QueryFormat.Properties.Resources.resources
WR
[NBF]root.Data
xxLq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xCC000 size 13832 bytes
Info
PDB Path: yaty.pdb
Module Name
yaty.exe
Full Name
yaty.exe
EntryPoint
System.Void QueryFormat.Program::Main()
Scope Name
yaty.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yaty
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
638
Main Method
System.Void QueryFormat.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QueryFormat.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yaty.exe
Full Name
yaty.exe
EntryPoint
System.Void QueryFormat.Program::Main()
Scope Name
yaty.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yaty
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
638
Main Method
System.Void QueryFormat.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QueryFormat.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QueryFormat.Forms.MainForm.resources
QueryFormat.Properties.Resources.resources
WR
[NBF]root.Data
xxLq
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙