Suspicious
Suspect

PE Executable
MD5: 8ea54a686d9f786351c7847d4b72e9f5
Size: 8.32 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8ea54a686d9f786351c7847d4b72e9f5
Sha1 a8873506b638d567ff54e068ac312e3f081ab0cd
Sha256 4e90fa3f4197c83ee858b522e2a99a8145da5e0f972f06a9b825e4a2781dc550
Sha384 1e743e82085fac7c24a026882fca36a77b854b82dc941ecaaf67d176c8fe89c5e7cc1a734b2f012e9a11307b56ed2d1c
Sha512 70253ab77ebced40018e1577981f0fcfd721e0cc246c1eed43f344d11ef407319d58d2a349b3a4f614e75409e7c5d1fa60792a95fc64b5dc54a6edb919e4e9e0
SSDeep 196608:VUcwti7TQlV/h/3a7fav6ehXkSIQo6uGO+Z8dWZehBFpQS/DGZ:3wtQQlhhC752kSVQ+xZehz+ED0
TLSH FD86339686EA575FD43E8C7D7C17EE1290EA64B0FE30430AC550F70D6C89D8C8FAA586
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
Onimai.exe
Full Name
Onimai.exe
EntryPoint
System.Void Program::Main()
Scope Name
Onimai.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Onimai
Assembly Version
1.7.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
66
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Module Name
Onimai.exe
Full Name
Onimai.exe
EntryPoint
System.Void Program::Main()
Scope Name
Onimai.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Onimai
Assembly Version
1.7.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
66
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
8ea54a686d9f786351c7847d4b72e9f5
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
8ea54a686d9f786351c7847d4b72e9f5
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙