Suspicious
Suspect

b353726ad20228ff61e25031f55f3e68

PE Executable
MD5: b353726ad20228ff61e25031f55f3e68
Size: 753.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 b353726ad20228ff61e25031f55f3e68
Sha1 12713faad59e24b207f78d52a97803ce55c25dfd
Sha256 c45640db87251995dc06c2ea4ef6ca5c0922df2b54819c84f4ef3477a4cd23c1
Sha384 9ee2063d4fea3185ce302a6772ef9e1cedd810add2411b815bfdd6a6f2afeb432e10209c070528105f7bf564882109e6
Sha512 b74c941484ffca746b19a33c8f40e19a8cde96e430471ccbceea7aea24068facff2b786c0f602608ee52d9b689e9168caea0cad35699ad615e6863d3c6dd1dc5
SSDeep 12288:vi1/3plPNnBpQvwSUyKzNy8sKszCiG5JoZe/mL1scwMirPMmU10LwoglRS+:aF5lPNBaSyR8sx9ao8uyMDHDl
TLSH DEF40105B439DE05C4A60BB4AB21EDF0037AAD9CB424E3575EEABDDF723A74110C1A5B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DamassaProject.fmrAdministrador.resources
DamassaProject.fmrListarUsuario.resources
$this.Icon
[NBF]root.IconData
MR
[NBF]root.Data
usuarioRepositoryBindingSource.TrayLocation
DamassaProject.fmrLogin.resources
pic_Imagem.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
pic_Logo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.fmrSplash.resources
pic_Image.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.Properties.Resources.resources
cHiJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
ooqo.exe
Full Name
ooqo.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
ooqo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ooqo
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
230
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ooqo.exe
Full Name
ooqo.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
ooqo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ooqo
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
230
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Embedded Resources UNKNWOWNsuspect
7huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DamassaProject.fmrAdministrador.resources
DamassaProject.fmrListarUsuario.resources
$this.Icon
[NBF]root.IconData
MR
[NBF]root.Data
usuarioRepositoryBindingSource.TrayLocation
DamassaProject.fmrLogin.resources
pic_Imagem.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
pic_Logo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.fmrSplash.resources
pic_Image.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.Properties.Resources.resources
cHiJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
b353726ad20228ff61e25031f55f3e68
Embedded Resources UNKNWOWNsuspect
7huhuhuhu
b353726ad20228ff61e25031f55f3e68
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
b353726ad20228ff61e25031f55f3e68
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙