Suspect
PE Executable
MD5: 9ebd8b5fa7aa04b7dbab2d04667f4690
Size: 978.94 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 9ebd8b5fa7aa04b7dbab2d04667f4690 |
| Sha1 | 3cb2272a8bd4d10a8931e022acce57d59a32820a |
| Sha256 | 084fd47a500e122be1ab53c87d6b679bbb34bd1de0d2df5ad8fc7fc75f006f26 |
| Sha384 | c3a9eeff31c798df4251eba3e84e4b73ffc384dd06863ad685c6897352fec0e7731a640005b5009612fdd1422c86a5c7 |
| Sha512 | 178f39f1d4587f6a84b4a9bbec5fa2e9138be666fa155b111a284757db65ecef0ffcfd534c7b5b1f88a256d8ba11e1800240996bfa6757871332cba2ca667075 |
| SSDeep | 24576:V/VpHZYG+7DdWAcA6WE8nirHZLEuOEMH:V/VxZ2hWtCEtFFk |
| TLSH | 1D251244221ADB02D4A71FF42960D2B457F9ADEAD832C30B9FDB1DAF792AB4549443C3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ousxh.pdb |
| Module Name | ousxh.exe |
| Full Name | ousxh.exe |
| EntryPoint | System.Void BullsCows.Program::Main() |
| Scope Name | ousxh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ousxh |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 324 |
| Main Method | System.Void BullsCows.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Module Name | ousxh.exe |
| Full Name | ousxh.exe |
| EntryPoint | System.Void BullsCows.Program::Main() |
| Scope Name | ousxh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ousxh |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 324 |
| Main Method | System.Void BullsCows.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.