Suspicious
Suspect

053981f06583f4024e1f51222f63c0bb

PE Executable
|
MD5: 053981f06583f4024e1f51222f63c0bb
|
Size: 686.08 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
053981f06583f4024e1f51222f63c0bb
Sha1
e2744c51a4688d7966748d16c89dbe115e4acfe6
Sha256
ce2a1e75336f3a8a1538a0019aaeeeaa3b69ee6fb86d4427b17d7d985fce4901
Sha384
ca963400b15533e03430dc205288ffc7e952444498fd6171424d91a86b4304ea2ddc608c4b60d8bad362055347ec313e
Sha512
3b7ee71a17ad13a067efeb87f347693f1a72da6b62d3470724b250ac91fc94fb22772da05cc6b7dfbf20217cdf152f54ca7117c0ffff8b9d38b0b74b65fe04b6
SSDeep
12288:ebqe/q/EjSOd4Tqv+3rrX1Q4db99V/Kpe8dpxqQ4UGKH4PuKfIgFIf6AC9:eW6CEcTqv6ri4L9hKpeueQzG04PPf1Fm
TLSH
F2E4125136C9CD12E8959BB858A1C3F921708ECCF403D30BEAEC5EFB7A2E62515A43C5

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PharmacyManager.Properties.Resources.resources
ecxv
[NBF]root.Data
[NBF]root.Data-preview.png
gr
[NBF]root.Data
Informations
Name
Value
Module Name

OgCm.exe

Full Name

OgCm.exe

EntryPoint

System.Void PharmacyManager.Program::Main()

Scope Name

OgCm.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OgCm

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void PharmacyManager.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PharmacyManager.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

OgCm.exe

Full Name

OgCm.exe

EntryPoint

System.Void PharmacyManager.Program::Main()

Scope Name

OgCm.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OgCm

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void PharmacyManager.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PharmacyManager.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
PDB Path

OgCm.pdb

053981f06583f4024e1f51222f63c0bb (686.08 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙