Suspicious
Suspect

PE Executable
MD5: e0fbb3b139096da7f116b2e8087d92d9
Size: 667.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e0fbb3b139096da7f116b2e8087d92d9
Sha1 fd54c9538f9b07eb05ce640ecd190d18a57b2c9a
Sha256 a649b5b04a26259cc8c92e558907389df2ddf89a2b2f8569ea51fbcc9c33b670
Sha384 67f149587f7e19e3d4ca612d564acd4cfdf5f2de3e020a549d72938a12dd943bc8800aacd1124eb3903aae32aa41d0e3
Sha512 65d0ad91e1b586f6f8c5852c5124cb3fbb625c01ed8eb4b5c6963e49fd7edaa37551cbb5cac73db79cee24439320582f83622780000bd45f3f1639b409f8439a
SSDeep 12288:Hrn4WEC70HmBOUqSXv72GqWCVMqCZ4u2id+ErKsVxxBHgPmfEifv5oW:HD4w7cUV/723WiJLuJw8VxxBH4msiH5
TLSH BCE4234439CDCA57C5E56EB80EA0F2B423786E1C8605C29BDFEB5C0FB8B379401166DA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SolarSystem.Azz.resources
SolarSystem.Form1.resources
$this.Icon
[NBF]root.IconData
Mars
[NBF]root.Data
contextMenuStrip1.TrayLocation
menuStrip1.TrayLocation
SolarSystem.Properties.Resources.resources
FlUZ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
oKUI.exe
Full Name
oKUI.exe
EntryPoint
System.Void SolarSystem.Program::Main()
Scope Name
oKUI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oKUI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
48
Main Method
System.Void SolarSystem.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SolarSystem.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
oKUI.exe
Full Name
oKUI.exe
EntryPoint
System.Void SolarSystem.Program::Main()
Scope Name
oKUI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oKUI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
48
Main Method
System.Void SolarSystem.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SolarSystem.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SolarSystem.Azz.resources
SolarSystem.Form1.resources
$this.Icon
[NBF]root.IconData
Mars
[NBF]root.Data
contextMenuStrip1.TrayLocation
menuStrip1.TrayLocation
SolarSystem.Properties.Resources.resources
FlUZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙