Suspicious
Suspect

0cfdc0a0851744c47cf8e7e1c11ec6a0

PE Executable
|
MD5: 0cfdc0a0851744c47cf8e7e1c11ec6a0
|
Size: 5.69 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

High

Hash
Hash Value
MD5
0cfdc0a0851744c47cf8e7e1c11ec6a0
Sha1
a8af3692f1c72d8543e04ea72f273df8b9188829
Sha256
2077ffbe110bcc4deebcac7210c6268015ae9682b12d859535108df8d1cb12da
Sha384
27e64cdfaa44073260a99cfd7adf4295d5a519f6273985c7854fe784cd902c239e1367fd3b35fe53dd1e1afee264df24
Sha512
bd915acec7df2515c122cac7260482e4b3e2e8140b9f884da2b1b89def846295ab310de9a2c72c7f492ad8b414c405a9e3b667d492dfcd948bf154d5ff16de45
SSDeep
98304:Qq9HPD8PjbpmaPWgOt2na45zk2xBTbDg:nspmbtyaGzLxRbD
TLSH
62469C03A29844E9D059C074CF469132EB62BC590BF666EF3690B6D62F77BD07B3A710

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual C++ v6.0 DLL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NewBalance.Properties.Resources.resources
_107_0_5304_106
_107_0_5304_107
[Authenticode]_47d74667.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.00cfg
.gxfg
.retplne
.tls
.voltbl
CPADinfo
_RDATA
malloc_h
.rsrc
.reloc
Resources
GOOGLEUPDATEAPPLICATIONCOMMANDS
ID:0001
ID:1033
RT_CURSOR
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
ID:000E
ID:0
ID:000F
ID:0
ID:0010
ID:0
ID:0011
ID:0
ID:0012
ID:0
ID:0013
ID:0
ID:0014
ID:0
ID:0015
ID:0
ID:0016
ID:0
ID:0017
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
ID:0011
ID:1033
ID:1033-preview.png
ID:0012
ID:1033
ID:0013
ID:1033
ID:0014
ID:1033
ID:0015
ID:1033
ID:1033-preview.png
ID:0016
ID:1033
ID:0017
ID:1033
ID:0018
ID:1033
ID:0019
ID:1033
ID:001A
ID:1033
ID:001B
ID:1033
ID:001C
ID:1033
ID:1033-preview.png
ID:001D
ID:1033
ID:001E
ID:1033
ID:001F
ID:1033
ID:0020
ID:1033
ID:0021
ID:1033
ID:0022
ID:1033
ID:0023
ID:1033
ID:1033-preview.png
ID:0024
ID:1033
ID:0025
ID:1033
ID:0026
ID:1033
ID:0027
ID:1033
ID:0028
ID:1033
ID:0029
ID:1033
ID:002A
ID:1033
ID:1033-preview.png
ID:002B
ID:1033
ID:002C
ID:1033
ID:002D
ID:1033
ID:002E
ID:1033
ID:002F
ID:1033
ID:0030
ID:1033
ID:0031
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR2
ID:93E4
ID:0
ID:93E5
ID:0
ID:93E6
ID:0
ID:93E7
ID:0
ID:93E8
ID:0
ID:93E9
ID:0
ID:93EA
ID:0
ID:93EB
ID:0
ID:93EC
ID:0
ID:93ED
ID:0
ID:93EE
ID:0
ID:93EF
ID:0
ID:93F0
ID:0
ID:93F1
ID:0
ID:93F2
ID:0
ID:93F3
ID:0
ID:93F4
ID:0
ID:93F5
ID:0
ID:93F6
ID:0
ID:93F7
ID:0
ID:93F8
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Authenticode]_568d04d7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.00cfg
.crthunk
.gxfg
.oldntma
.retplne
.tls
.voltbl
CPADinfo
_RDATA
malloc_h
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
version_c
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.pdb.compressed
costura.system.diagnostics.diagnosticsource.dll.compressed
[Authenticode]_50c89911.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.zlib.net.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.metadata
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: D:\_Projects\C#\2022\LogitechV2\NewBalance\obj\Release\NewBalance.pdb

Module Name

NewBalance.exe

Full Name

NewBalance.exe

EntryPoint

System.Void NewBalance.pgftficzlrpg::Main(System.String[])

Scope Name

NewBalance.exe

Scope Type

ModuleDef

Kind

Console

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NewBalance

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

116

Main Method

System.Void NewBalance.pgftficzlrpg::Main(System.String[])

Main IL Instruction Count

40

Main IL

ldsfld System.String System.String::Empty stsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr newobj System.Void System.Random::.ctor() stloc.0 <null> ldc.i4.0 <null> stloc.1 <null> br.s IL_0038: ldloc.1 ldsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr ldloc.0 <null> ldc.i4.0 <null> ldc.i4.s 10 callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) stloc.2 <null> ldloca.s V_2 call System.String System.Int32::ToString() call System.String System.String::Concat(System.String,System.String) stsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr ldloc.1 <null> ldc.i4.1 <null> add <null> stloc.1 <null> ldloc.1 <null> ldc.i4.5 <null> blt.s IL_0014: ldsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr newobj System.Void System.Windows.Forms.Form::.ctor() stsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldnull <null> ldftn System.Void NewBalance.pgftficzlrpg::ggavzjgardft(System.Object,System.EventArgs) newobj System.Void System.EventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.Windows.Forms.Form::add_Load(System.EventHandler) ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldnull <null> ldftn System.Void NewBalance.pgftficzlrpg::lghkyynbwfzn(System.Object,System.Windows.Forms.FormClosingEventArgs) newobj System.Void System.Windows.Forms.FormClosingEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.Windows.Forms.Form::add_FormClosing(System.Windows.Forms.FormClosingEventHandler) ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog() pop <null> ret <null>

Module Name

NewBalance.exe

Full Name

NewBalance.exe

EntryPoint

System.Void NewBalance.pgftficzlrpg::Main(System.String[])

Scope Name

NewBalance.exe

Scope Type

ModuleDef

Kind

Console

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NewBalance

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

116

Main Method

System.Void NewBalance.pgftficzlrpg::Main(System.String[])

Main IL Instruction Count

40

Main IL

ldsfld System.String System.String::Empty stsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr newobj System.Void System.Random::.ctor() stloc.0 <null> ldc.i4.0 <null> stloc.1 <null> br.s IL_0038: ldloc.1 ldsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr ldloc.0 <null> ldc.i4.0 <null> ldc.i4.s 10 callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) stloc.2 <null> ldloca.s V_2 call System.String System.Int32::ToString() call System.String System.String::Concat(System.String,System.String) stsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr ldloc.1 <null> ldc.i4.1 <null> add <null> stloc.1 <null> ldloc.1 <null> ldc.i4.5 <null> blt.s IL_0014: ldsfld System.String NewBalance.pgftficzlrpg::ojlpklrtykkr newobj System.Void System.Windows.Forms.Form::.ctor() stsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldnull <null> ldftn System.Void NewBalance.pgftficzlrpg::ggavzjgardft(System.Object,System.EventArgs) newobj System.Void System.EventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.Windows.Forms.Form::add_Load(System.EventHandler) ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe ldnull <null> ldftn System.Void NewBalance.pgftficzlrpg::lghkyynbwfzn(System.Object,System.Windows.Forms.FormClosingEventArgs) newobj System.Void System.Windows.Forms.FormClosingEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.Windows.Forms.Form::add_FormClosing(System.Windows.Forms.FormClosingEventHandler) ldsfld System.Windows.Forms.Form NewBalance.pgftficzlrpg::whqshquxjghe callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog() pop <null> ret <null>

0cfdc0a0851744c47cf8e7e1c11ec6a0 (5.69 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙