Malicious
Malicious

c8a7ae786c0294734130e1685a6f5ae3

PE Executable
MD5: c8a7ae786c0294734130e1685a6f5ae3
Size: 1.22 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 c8a7ae786c0294734130e1685a6f5ae3
Sha1 98c8c5d84a81cc068d24a68b1e2bb3dc7babae41
Sha256 9aa928b433983f53758e42961aa0cf8096a4211a5562bfcd7ba3cb63d902282b
Sha384 0b0711556c32bb64d00d82ee8f21058e93129d999ba3709ae98c238b494a39586b50ed54c7cc1c37419260d3fc261ea9
Sha512 27d3d8c81ead2f699f37a966b57930af033d024d7288c66f2b118b5600496fc4a2db0aac0caae38ffc4ba52ada866a7531ef50849b9d656a1579d5c68a9690ac
SSDeep 24576:nwlJtvWmBwtBFMkPSrNazB9SuPq47lChYLD6pHa:PoQBFvSrNazB9SmfiOD6J
TLSH 6E452358A7ABD542C461037388E1F2B293B28E49F633D32FABDD3DE7B1253465E46241
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
N7y.y74.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
a7v.h7K.resources
Ozuv.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
KEiR
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Ozuv.pdb
Module Name
Ozuv.exe
Full Name
Ozuv.exe
EntryPoint
System.Void pk.ri::rh()
Scope Name
Ozuv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ozuv
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void pk.ri::rh()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void Hfh.Yfk::eNQ()
call System.Void Hfh.Yfk::eNQ()
br IL_001D: nop
nop <null>
ret <null>
nop <null>
newobj System.Void N7y.y74::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001B: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
Module Name
Ozuv.exe
Full Name
Ozuv.exe
EntryPoint
System.Void pk.ri::rh()
Scope Name
Ozuv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ozuv
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void pk.ri::rh()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void Hfh.Yfk::eNQ()
call System.Void Hfh.Yfk::eNQ()
br IL_001D: nop
nop <null>
ret <null>
nop <null>
newobj System.Void N7y.y74::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001B: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
N7y.y74.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
a7v.h7K.resources
Ozuv.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
KEiR
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙