Malicious
c8a7ae786c0294734130e1685a6f5ae3
PE Executable
MD5: c8a7ae786c0294734130e1685a6f5ae3
Size: 1.22 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | c8a7ae786c0294734130e1685a6f5ae3 |
| Sha1 | 98c8c5d84a81cc068d24a68b1e2bb3dc7babae41 |
| Sha256 | 9aa928b433983f53758e42961aa0cf8096a4211a5562bfcd7ba3cb63d902282b |
| Sha384 | 0b0711556c32bb64d00d82ee8f21058e93129d999ba3709ae98c238b494a39586b50ed54c7cc1c37419260d3fc261ea9 |
| Sha512 | 27d3d8c81ead2f699f37a966b57930af033d024d7288c66f2b118b5600496fc4a2db0aac0caae38ffc4ba52ada866a7531ef50849b9d656a1579d5c68a9690ac |
| SSDeep | 24576:nwlJtvWmBwtBFMkPSrNazB9SuPq47lChYLD6pHa:PoQBFvSrNazB9SmfiOD6J |
| TLSH | 6E452358A7ABD542C461037388E1F2B293B28E49F633D32FABDD3DE7B1253465E46241 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: Ozuv.pdb |
| Module Name | Ozuv.exe |
| Full Name | Ozuv.exe |
| EntryPoint | System.Void pk.ri::rh() |
| Scope Name | Ozuv.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Ozuv |
| Assembly Version | 4.2.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 69 |
| Main Method | System.Void pk.ri::rh() |
| Main IL Instruction Count | 16 |
| Main IL | |
| Module Name | Ozuv.exe |
| Full Name | Ozuv.exe |
| EntryPoint | System.Void pk.ri::rh() |
| Scope Name | Ozuv.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Ozuv |
| Assembly Version | 4.2.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 69 |
| Main Method | System.Void pk.ri::rh() |
| Main IL Instruction Count | 16 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.