Suspicious
Suspect

PE Executable
MD5: 953323775d5923cea85b30116152d97b
Size: 726.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 953323775d5923cea85b30116152d97b
Sha1 8e64ecac580e56b5ce25025d475dce766c5f6eef
Sha256 8a66d39f70c5e10e1cc7b7b108ac259281682ec4a09dbee9962e27ea4c5ad2b9
Sha384 711398e5e65c3de70a053c53d6bac5f0e6a09f7502554dc922e101079899e067d67d07b0fe6786dfe3192f0d4b41d8e3
Sha512 f0e15212fb7eb0d5d6754f496db26a54990325da9f601d2bcbc522a9d591503274a0d9410109bd335bea836ee2990a706f34c7f632cce41a1753da6b2eb938d1
SSDeep 12288:hGnqbdvnJ5r8xXqLlTRWP3uAmJm97dwVXpzqE5m1pvP2R+qEAqg1A:hGnqbFr8B25AaUaBoI81obBb1
TLSH BCF412A4365BE219C4926BB45A72F27817796E9CF912D61B9EDC7EEFB435B000D002C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
nyWe
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ocRu.pdb
Module Name
ocRu.exe
Full Name
ocRu.exe
EntryPoint
System.Void WordLength.Program::Main()
Scope Name
ocRu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ocRu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
182
Main Method
System.Void WordLength.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordLength.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
nyWe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙