Suspicious
Suspect

0254a7e0582b2be5443eadcc8bdf6806

PE Executable
|
MD5: 0254a7e0582b2be5443eadcc8bdf6806
|
Size: 1.07 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
0254a7e0582b2be5443eadcc8bdf6806
Sha1
1de39e20fa3babfd586f5edc08a9ae3625d4cf2a
Sha256
7a020ca579b3ef573ceaaf0ab51c6c38e27f15dde073053e2772b0656de370f3
Sha384
b0d6828a178c5698b3b4964010b41c93b3c6222897ff5c275f55e02c52498cea4c59bd63e895504697262efba54e73b8
Sha512
9b5c5a9d4485fa475633a0d8c71b87496642fe4659880144ae5034f8d448ab7ae0cd8db3dd766b7fa1e71918fda4a0c0d109fabfa9aa0bff36852b7df0f60ec1
SSDeep
24576:ZPdiLzYmGFJ5YB/M537YZGl5f5Wey7YZ5mI8RNpjxTn7QbZ:O8mGD5Y+5YEddy7XI8RVkb
TLSH
9A3522A4B419EA53CEAA46F44C22F3B047769CBA7417C7D98EDE6FCB75E0B501000A67

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Countdown_App.appForm.resources
$this.Icon
[NBF]root.IconData
Num
[NBF]root.Data
errorProvider1.TrayLocation
timer1.TrayLocation
Countdown_App.Properties.Resources.resources
_22
[NBF]root.Data
[NBF]root.Data-preview.png
_23
[NBF]root.Data
[NBF]root.Data-preview.png
fqVfR
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\QSCKsKQbKK\src\obj\Debug\Ufsau.pdb

Module Name

Ufsau.exe

Full Name

Ufsau.exe

EntryPoint

System.Void Countdown_App.Program::Main()

Scope Name

Ufsau.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ufsau

Assembly Version

4.2.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

257

Main Method

System.Void Countdown_App.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Countdown_App.appForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

Ufsau.exe

Full Name

Ufsau.exe

EntryPoint

System.Void Countdown_App.Program::Main()

Scope Name

Ufsau.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ufsau

Assembly Version

4.2.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

257

Main Method

System.Void Countdown_App.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Countdown_App.appForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

0254a7e0582b2be5443eadcc8bdf6806 (1.07 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Countdown_App.appForm.resources
$this.Icon
[NBF]root.IconData
Num
[NBF]root.Data
errorProvider1.TrayLocation
timer1.TrayLocation
Countdown_App.Properties.Resources.resources
_22
[NBF]root.Data
[NBF]root.Data-preview.png
_23
[NBF]root.Data
[NBF]root.Data-preview.png
fqVfR
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙