Suspicious
Suspect

045c95649ebfe3c039324cbd70f7744a

PE Executable
|
MD5: 045c95649ebfe3c039324cbd70f7744a
|
Size: 729.09 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
045c95649ebfe3c039324cbd70f7744a
Sha1
51577956c1be21d4dad8810d46dbafcc89ee0721
Sha256
45c64c04137dbd68881ec07852bf10e7c491f504e1f78247b1217114cab47d3e
Sha384
3b9988b310ba16bbb8e01a3e0728eb6d7a8c5abf63e10f9b3f2c1253ba14bf77963859f28473e3171c1b6856a327aac0
Sha512
5331a4c7819de96d3efb1ae363958bf67f49dfb1449530137ef90948eecde32daa2ae31213e6a35219b7ed569857fcbdd9cdeb683980ff893f257d12067be1b0
SSDeep
12288:ReoeStF07+EagoDr5VHffo3YWarVNxX+lp6s73xU85u8hg5AK8rvAOFHSEQhan2l:RnF07v8v/ftWaxNxX46s+GK8bAOj/on
TLSH
16F41259238AD515D1F53B382DB2D378837E3D89A832C31A4BE96CDF7C36B5098117A2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
kiwr
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: IsYo.pdb

Module Name

IsYo.exe

Full Name

IsYo.exe

EntryPoint

System.Void StudyGuide.Program::Main()

Scope Name

IsYo.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

IsYo

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

101

Main Method

System.Void StudyGuide.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void StudyGuide.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

IsYo.exe

Full Name

IsYo.exe

EntryPoint

System.Void StudyGuide.Program::Main()

Scope Name

IsYo.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

IsYo

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

101

Main Method

System.Void StudyGuide.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void StudyGuide.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

045c95649ebfe3c039324cbd70f7744a (729.09 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙