Suspicious
Suspect

0a70680eda6c8e5bf6538f5b49871ee9

PE Executable
|
MD5: 0a70680eda6c8e5bf6538f5b49871ee9
|
Size: 1.3 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
0a70680eda6c8e5bf6538f5b49871ee9
Sha1
645e83b27628e5cc83cf1652517ba989e31e6251
Sha256
89be0060e88e37f5b5c3736fff092b5cd6e89eea26c6b4438e8932e7925a4837
Sha384
6b75f83c5d93ebfa7364a52a6d0230295fd6fcf04323944631be32340dbefa0e4e3afca91b5d9eedcf1317eee0a116b2
Sha512
377d1da109bfa5940f5a1cc4989b0cc9165913fa0edb11e17d26cb4515e81cd45287ad17c238fc4c996a63b20479143cc61d374f03b354557b3f6d337d25ccb9
SSDeep
24576:65b9Xf2cBC5LKQCnRveYepqMKDmfC4KOSSn2I6:6BacRveYkqM3fC41p2
TLSH
7455AE6E23E16A90FB3F1EF0C2B8A545A3F0A0DF0950C76953D5C2E667273C67E82551

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Qaseneyen.zitarsan
Htz0r7y.Resources.resources
11e5d3ce5c0c12.Resources.resources
e1ce601d0
[NBF]root.Data
e1ce601d1
[NBF]root.Data
e1ce601d10
[NBF]root.Data
e1ce601d11
[NBF]root.Data
e1ce601d12
[NBF]root.Data
e1ce601d13
[NBF]root.Data
e1ce601d14
[NBF]root.Data
e1ce601d15
[NBF]root.Data
e1ce601d16
[NBF]root.Data
e1ce601d17
[NBF]root.Data
e1ce601d18
[NBF]root.Data
e1ce601d19
[NBF]root.Data
e1ce601d2
[NBF]root.Data
e1ce601d20
[NBF]root.Data
e1ce601d21
[NBF]root.Data
e1ce601d22
[NBF]root.Data
e1ce601d23
[NBF]root.Data
e1ce601d24
[NBF]root.Data
e1ce601d25
[NBF]root.Data
e1ce601d26
[NBF]root.Data
e1ce601d27
[NBF]root.Data
e1ce601d28
[NBF]root.Data
e1ce601d29
[NBF]root.Data
e1ce601d3
[NBF]root.Data
e1ce601d30
[NBF]root.Data
e1ce601d31
[NBF]root.Data
e1ce601d32
[NBF]root.Data
e1ce601d33
[NBF]root.Data
e1ce601d34
[NBF]root.Data
e1ce601d35
[NBF]root.Data
e1ce601d36
[NBF]root.Data
e1ce601d37
[NBF]root.Data
e1ce601d38
[NBF]root.Data
e1ce601d39
[NBF]root.Data
e1ce601d4
[NBF]root.Data
e1ce601d40
[NBF]root.Data
e1ce601d41
[NBF]root.Data
e1ce601d5
[NBF]root.Data
e1ce601d6
[NBF]root.Data
e1ce601d7
[NBF]root.Data
e1ce601d8
[NBF]root.Data
e1ce601d9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Htz0r7y

Full Name

Htz0r7y

EntryPoint

System.Void Htz0r7y.UserControls.jd0THdb6b::3CnqosW()

Scope Name

Htz0r7y

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Htz0r7y

Assembly Version

5.16.23.255

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

3432

Main Method

System.Void Htz0r7y.UserControls.jd0THdb6b::3CnqosW()

Main IL Instruction Count

14

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldstr zitarsan call System.Void Htz0r7y.Tc0epdE3Rz5::re1YLbx6(System.String) nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::Exit() nop <null> ret <null>

Module Name

Htz0r7y

Full Name

Htz0r7y

EntryPoint

System.Void Htz0r7y.UserControls.jd0THdb6b::3CnqosW()

Scope Name

Htz0r7y

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Htz0r7y

Assembly Version

5.16.23.255

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

3432

Main Method

System.Void Htz0r7y.UserControls.jd0THdb6b::3CnqosW()

Main IL Instruction Count

14

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldstr zitarsan call System.Void Htz0r7y.Tc0epdE3Rz5::re1YLbx6(System.String) nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::Exit() nop <null> ret <null>

0a70680eda6c8e5bf6538f5b49871ee9 (1.3 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙