MalScore
100/100
MalFamily
Razy

nytbin.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 19/68 Related 2238
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 647.00 KB (662528 bytes)
Compile time: 1996-07-06 18:31:01
MD5: c587d0b498c4f1b9c104b907832bf362
SHA1: 23d16b37084cf68ef78675e9bbbc3cc8b07caec8
SHA256: c953411d7646c175a693db7f249e7a7ee81014dad5bde642b15b41e9737708f3
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-11-08 13:06:04
Last submission: 2018-11-08 13:06:04
Filename detected: - nytbin.exe (1)
URL file hosting
hXXps://ougadikhalkhuntec.nl/hgb/nytbin.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-11-07 04:17:12 [19/68] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xa0f64 659456 877ffe7ca9eba37542a4a041b5eb1aff b29c1d1da4e4713cdba0683fee840ac62ace82ac
.rsrc 0xa4000 0x674 2048 5989b2feddfa03707dc4c362b76a6f24 f0996fbd824fec341f890b34c2c870db0b92d0f5
.reloc 0xa6000 0xc 512 4ba9579f0ffe8a86486b53961e04f95a 144928d1102027f6b1c79636536571e0d56be98f
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
System.Xml
FIle type: Library
mscoree.dll
IP Found
16.14.17.3
URL(s)
No URL found
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2018-11-08 12:58:08 2018-11-08 13:01:07 179

1 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2018-11-08 12:58:08 2018-11-08 13:01:07 179

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-11-08 13:06:21

Detected family: #Razy

TheSystem Itself @ 2018-11-08 13:10:02