Suspicious
Suspect

PE Executable
MD5: 9ebd8b5fa7aa04b7dbab2d04667f4690
Size: 978.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9ebd8b5fa7aa04b7dbab2d04667f4690
Sha1 3cb2272a8bd4d10a8931e022acce57d59a32820a
Sha256 084fd47a500e122be1ab53c87d6b679bbb34bd1de0d2df5ad8fc7fc75f006f26
Sha384 c3a9eeff31c798df4251eba3e84e4b73ffc384dd06863ad685c6897352fec0e7731a640005b5009612fdd1422c86a5c7
Sha512 178f39f1d4587f6a84b4a9bbec5fa2e9138be666fa155b111a284757db65ecef0ffcfd534c7b5b1f88a256d8ba11e1800240996bfa6757871332cba2ca667075
SSDeep 24576:V/VpHZYG+7DdWAcA6WE8nirHZLEuOEMH:V/VxZ2hWtCEtFFk
TLSH 1D251244221ADB02D4A71FF42960D2B457F9ADEAD832C30B9FDB1DAF792AB4549443C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BullsCows.Formularios.FormularioMenu.resources
BullsCows.Properties.Resources.resources
Capo
[NBF]root.Data
x
[NBF]root.Data
[NBF]root.Data-preview.png
xgoKN
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ousxh.pdb
Module Name
ousxh.exe
Full Name
ousxh.exe
EntryPoint
System.Void BullsCows.Program::Main()
Scope Name
ousxh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ousxh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
324
Main Method
System.Void BullsCows.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BullsCows.Formularios.FormularioMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ousxh.exe
Full Name
ousxh.exe
EntryPoint
System.Void BullsCows.Program::Main()
Scope Name
ousxh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ousxh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
324
Main Method
System.Void BullsCows.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BullsCows.Formularios.FormularioMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BullsCows.Formularios.FormularioMenu.resources
BullsCows.Properties.Resources.resources
Capo
[NBF]root.Data
x
[NBF]root.Data
[NBF]root.Data-preview.png
xgoKN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙