Suspicious
Suspect

PE Executable
MD5: 4bb81a2d7409c70fc1e7a7aa8e7e7a65
Size: 1.01 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4bb81a2d7409c70fc1e7a7aa8e7e7a65
Sha1 4d2766551309a9c4ff549b066d7f3d9b36a78b7e
Sha256 44f1a67e4a326b1f751b8e0671a46ff65acd9c8e9c515c764c41c87c3bf9cca8
Sha384 b9b6312abb26fe80116f1c24909c1c5d38b2ef6799daa16f2efcb1c270318b71e11c1c5f82e154263ab163f8e856b69a
Sha512 0377f20243846e754b1bfba13a3e607f05e24ef5c4925e7013ce25e17eccac2ac7d061bd0100aa4f3370d14503a4df5587a0bec196e902cbf32ea03b65dcafaa
SSDeep 24576:ooZnXqyllglglglvRsA9OMAdI5ltWdJfYSacM5QM1RGcZ:J6FYmx8J5RQ
TLSH F42501D133A9DD03D5B451F2D421E2744BF56DABB822C3E48ED96CCB7AE4F426242983
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
HXlS
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ZOfGQIlbGQ\src\obj\Debug\Ozje.pdb
Module Name
Ozje.exe
Full Name
Ozje.exe
EntryPoint
System.Void IndexApp.Program::Main()
Scope Name
Ozje.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ozje
Assembly Version
3.4.6.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
749
Main Method
System.Void IndexApp.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void IndexApp.IndexApp::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
HXlS
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙