Suspicious
Suspect

PE Executable
MD5: cee23114ee0a49913578af4341371328
Size: 801.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cee23114ee0a49913578af4341371328
Sha1 48aa7f22e482baccfdc6b6eb9f3163f5510352b8
Sha256 399c51d6ed22fb0c649d5a148aaef55eee07060251dde6ed045c188d2f4c8b4a
Sha384 2850aeb745c02ee9702c88779a3f0b9cc27909d21ddbe52227433d490eb8ce4e2211971895df531a00e0e32471c38eb7
Sha512 ecac865636b67b45caf04d688b958c0d6ffda49680239f1c44a1169af5e334a718f384434ad386b7ab9030075a2cfd5a9ecf0a79e77637ffb2f935f99c15a52f
SSDeep 24576:27ukcmLXFmZDxMuF9O+A8CxZ+d+FF4dsZo:27uk9VeilzH+d+FudsZ
TLSH 04050100F259FC0FC15B87B498A0D1F10F78AEDAE502FA475EE07E8B7876B705626196
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
TwRc
[NBF]root.Data
[NBF]root.Data-preview.png
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\cpoBpvPOhl\src\obj\Debug\ocGH.pdb
Module Name
ocGH.exe
Full Name
ocGH.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
ocGH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ocGH
Assembly Version
3.6.1.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ocGH.exe
Full Name
ocGH.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
ocGH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ocGH
Assembly Version
3.6.1.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
TwRc
[NBF]root.Data
[NBF]root.Data-preview.png
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙