Suspicious
Suspect

04a5bd8312cf2df5f0d37b08954f433a

PE Executable
|
MD5: 04a5bd8312cf2df5f0d37b08954f433a
|
Size: 964.61 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
04a5bd8312cf2df5f0d37b08954f433a
Sha1
dbf240c63a7b89162a1d27c965cf39750bff50cb
Sha256
bdd6a6c3625c13560f610c7265fca6d99d53cef86054269da6c84c5dfd808539
Sha384
688e5024913873bcae1d27fd8e027e5e0cab472345ec188ed0505a3f4f566f11e138e9a7c5a3384190ba13d20c24e9ab
Sha512
0c268f789111792637f75d8b382e0b9dd2956781c642256869710e027b20fbf6ac21f50f86b3028bcd2fc9ff12e97c6b306d06e729f1d42b9ad24843502ccf7e
SSDeep
24576:ucjc6LCxAVOe0Ea4TdDCKFTbr9WsvmJ8/h+36wg:7Q6LCZ4pDfT9W+m2h+h
TLSH
E925125EBF6AEA56CE4C0FFBC452240881B58547D462F3A749C829F21F25F8CC68E953

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Informations
Name
Value
Module Name

wGcB.exe

Full Name

wGcB.exe

EntryPoint

System.Void AlarmPlus.Program::Main()

Scope Name

wGcB.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

wGcB

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void AlarmPlus.Program::Main()

Main IL Instruction Count

33

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void AlarmPlus.WorldClockForm::Ⴅ() ldc.i4 1002 ldc.i4 954 call System.Void AlarmPlus.Properties.Resources::Ⴈ(System.Int32,System.Int32) ldc.i4.0 <null> ldc.i4 878 ldc.i4 890 call System.Void AlarmPlus.AlarmForm::Ⴄ(System.Boolean,System.Char,System.Int16) ldc.i4.2 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void AlarmPlus.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 200 ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 200 ldelem.u2 <null> ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 299 ldelem.u2 <null> sub <null> ldc.i4 176 and <null> stelem.i2 <null> ret <null> ldtoken System.Void AlarmPlus.Program::Main() pop <null> ret <null>

Module Name

wGcB.exe

Full Name

wGcB.exe

EntryPoint

System.Void AlarmPlus.Program::Main()

Scope Name

wGcB.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

wGcB

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void AlarmPlus.Program::Main()

Main IL Instruction Count

33

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void AlarmPlus.WorldClockForm::Ⴅ() ldc.i4 1002 ldc.i4 954 call System.Void AlarmPlus.Properties.Resources::Ⴈ(System.Int32,System.Int32) ldc.i4.0 <null> ldc.i4 878 ldc.i4 890 call System.Void AlarmPlus.AlarmForm::Ⴄ(System.Boolean,System.Char,System.Int16) ldc.i4.2 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void AlarmPlus.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 200 ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 200 ldelem.u2 <null> ldsfld System.Char[] AlarmPlus.AlarmManager::Ⴍ ldc.i4 299 ldelem.u2 <null> sub <null> ldc.i4 176 and <null> stelem.i2 <null> ret <null> ldtoken System.Void AlarmPlus.Program::Main() pop <null> ret <null>

04a5bd8312cf2df5f0d37b08954f433a (964.61 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙