Suspicious
Suspect

PE Executable
MD5: 7252f757910e9c1e29008b7d720d377b
Size: 686.59 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 7252f757910e9c1e29008b7d720d377b
Sha1 13168b8596c32e855037583ca977cf342edc8dc0
Sha256 8024fb977a8ce280bd9bbe8984c2a1eb02a39c82222940de7b8951fc1493cd80
Sha384 50c8ca646cc4ebda570521f383da821d05ff16aaaa9d99d6fd6160df154333563294b562f0c6a557376f47a7046e5982
Sha512 14652ec2c87d5f43582b6e59ecce23586019817680b91e88ee3579105795ea0a6ee69d0bbab0eef3b748f5886c14e04dec0efc8096d3f9272e408921933cd18d
SSDeep 12288:qG58Ei/GihAuYJkqYAlK7F9qZQI43kYsqYohflFA50pYF/1bD4:NxiphA3Plu9Ib40YhLXAhbD4
TLSH 1CE4120EFA987B1AD5260B7A881B0155D6F12826F122F69F74C918D52F36FC4809FB4F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
OCgV.exe
Full Name
OCgV.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
OCgV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OCgV
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Byte[] SecureMode.ProfessionalForm53::Ⴃ
stloc.2 <null>
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.AdvancedForm20::Ⴄ()
ldc.i4.s 26
ldc.i4.s 119
call System.Void SecureMode.AsyncForm59::Ⴈ(System.Char,System.Int32)
ldc.i4.0 <null>
ldc.i4 478
ldc.i4 467
call System.Void SecureMode.Program::Ⴓ(System.Boolean,System.Char,System.Char)
ldloc.2 <null>
ldc.i4 252
ldelem.u1 <null>
ldc.i4 197
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Module Name
OCgV.exe
Full Name
OCgV.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
OCgV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OCgV
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Byte[] SecureMode.ProfessionalForm53::Ⴃ
stloc.2 <null>
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.AdvancedForm20::Ⴄ()
ldc.i4.s 26
ldc.i4.s 119
call System.Void SecureMode.AsyncForm59::Ⴈ(System.Char,System.Int32)
ldc.i4.0 <null>
ldc.i4 478
ldc.i4 467
call System.Void SecureMode.Program::Ⴓ(System.Boolean,System.Char,System.Char)
ldloc.2 <null>
ldc.i4 252
ldelem.u1 <null>
ldc.i4 197
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWN
0huhuhuhu
7252f757910e9c1e29008b7d720d377b
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
7252f757910e9c1e29008b7d720d377b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙