Suspicious
Suspect

08f2ba7fd72e6d58b28c84b2955fede9

PE Executable
|
MD5: 08f2ba7fd72e6d58b28c84b2955fede9
|
Size: 727.04 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
08f2ba7fd72e6d58b28c84b2955fede9
Sha1
476fa4f570d4d156e4351df1d7aa60052541405e
Sha256
d04cf401daa99d9633590e81aa8b4985b7de8193394d1422088ecd68ed933d2a
Sha384
d092c25783fecd4f9c5bece72effc8ddf665b5d8274b295004d4b5be53ba49967bd0b8cb93ab46b4190164d93fe941e8
Sha512
c127d4ef9f21f2f84bffe5b8b6119560d53fac02f5abc91a2d4f7fb6ee215a7be3c064d3123582d82c3dac9d43d1eb68d6264f292e4fee7d729c2e086486caa7
SSDeep
12288:/zQLOwUNTLdwDPeQJqLGaS6AK2eUSIpbNX8joIpyKGter3y7JZC+p+Utawe1I7qQ:/zQBiR9S6x2eUSI8joIsKMejMJZxsa3r
TLSH
9CF412422726DE17E4A11BF89DA2E3B807B85E9DB800D3475FE97DF7793138466402A3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsContacts.AddEditContactForm.resources
WindowsContacts.Properties.Resources.resources
KOp
[NBF]root.Data
jPI
[NBF]root.Data
[NBF]root.Data-preview.png
kupa
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: hef.pdb

Module Name

hef.exe

Full Name

hef.exe

EntryPoint

System.Void WindowsContacts.Program::Main()

Scope Name

hef.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hef

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

208

Main Method

System.Void WindowsContacts.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsContacts.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

hef.exe

Full Name

hef.exe

EntryPoint

System.Void WindowsContacts.Program::Main()

Scope Name

hef.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hef

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

208

Main Method

System.Void WindowsContacts.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsContacts.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

08f2ba7fd72e6d58b28c84b2955fede9 (727.04 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙