Suspicious
Suspect

040911e5e9cf102ac043bc80990c14e9

PE Executable
|
MD5: 040911e5e9cf102ac043bc80990c14e9
|
Size: 1.1 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
040911e5e9cf102ac043bc80990c14e9
Sha1
0e86ddf5f232808ddd4ff967c3693fdd5b201fb9
Sha256
046c2cefcb304a84206b4d598b07b947ffbe7786d6df1048750c2fb08f224352
Sha384
91df81f286ceab4d369355d22cb03ed3051d84973e6ba90a3794665b52a58e46dbb0af11134e38d83270b1deee46426d
Sha512
195d79403d85de57a33616cf940021ffc9c017a15a4885d5ba3bf912e423ff708a55961b4025aa512874118b2648e65baa47c2a9e1fe23e37490650de121365c
SSDeep
24576:Ldd7QCEcg2/cJOSwHIgHeYXzzxEbABCPes7zWq4xII:rEf2/AkHIczzSbKWeUtkI
TLSH
DF3512AD2684C223ED95C37C1AB3E67453B50DA9E821C2128FEDEDD77140BCDA518ED2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinSimulator.Form3.resources
$this.Icon
[NBF]root.IconData
CoinSimulator.Properties.Resources.resources
GT8
[NBF]root.Data
gXiQSSS
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

ILegacyEvidenceAdap

Full Name

ILegacyEvidenceAdap

EntryPoint

System.Void ObjectHandleOnSt.TimerQu::Main()

Scope Name

ILegacyEvidenceAdap

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SusyKjx

Assembly Version

5.4.2.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

158

Main Method

System.Void ObjectHandleOnSt.TimerQu::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void GetEnumerator.CMSFILEHASHALGORI::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

ILegacyEvidenceAdap

Full Name

ILegacyEvidenceAdap

EntryPoint

System.Void ObjectHandleOnSt.TimerQu::Main()

Scope Name

ILegacyEvidenceAdap

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SusyKjx

Assembly Version

5.4.2.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

158

Main Method

System.Void ObjectHandleOnSt.TimerQu::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void GetEnumerator.CMSFILEHASHALGORI::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

040911e5e9cf102ac043bc80990c14e9 (1.1 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinSimulator.Form3.resources
$this.Icon
[NBF]root.IconData
CoinSimulator.Properties.Resources.resources
GT8
[NBF]root.Data
gXiQSSS
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙