Threat Database Trojans Trojan.Occamy.B

Trojan.Occamy.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,508
Threat Level: 80 % (High)
Infected Computers: 1,343
First Seen: July 1, 2021
Last Seen: December 30, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Occamy.B
Signature status: No Signature

Known Samples

MD5: 4389b956a9d3cbaac244f1845c9a3d0c
SHA1: bbad128b0c30cc306166194731b262e9132585b3
SHA256: B448F4121632F8040FF312113FDD2C592DE33D3642481A22E262F26B84222E5F
File Size: 1.80 MB, 1801516 bytes
MD5: 18e8a88cbfe55575df3eab4931d33c8a
SHA1: df5d8b3ed85a976a8195454b5719ae300a8d52a8
SHA256: 86B54C7470190C6D398CCD38AFFE0FA2975BF38F02E6129E7311ACCC319FFEA3
File Size: 2.29 MB, 2286592 bytes
MD5: 9461e6a739e25c8b4e2ef7bf7a76bbdd
SHA1: e8186418cd85a84dd8e3962827072266e51d9c21
SHA256: 3AB8C3E566A36E6B0608958090FD34D4ADD720F15679096D964B64A8A80602B5
File Size: 1.84 MB, 1842688 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • ON Connect
  • PLAYER MANDO SPORT
File Version
  • 1.00
  • 1.0.0.0
Internal Name
  • ON Connect.exe
  • PLAYER MANDO SPORT.exe
  • TJprojMain
Legal Copyright
  • Copyright © 2024
  • Copyright © 2025
Original Filename
  • ON Connect.exe
  • PLAYER MANDO SPORT.exe
  • TJprojMain.exe
Product Name
  • ON Connect
  • PLAYER MANDO SPORT
  • Project1
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • .NET
  • 2+ executable sections
  • HighEntropy
  • NewLateBinding
  • x86

Block Information

Total Blocks: 192
Potentially Malicious Blocks: 0
Whitelisted Blocks: 190
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DiscordStealer.FR
  • MSIL.DiscordStealer.RS
  • Occamy.B

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...