Suspicious
Suspect

0e47982164bb3b099ed24e96cbe5589e

PE Executable
|
MD5: 0e47982164bb3b099ed24e96cbe5589e
|
Size: 2.15 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
0e47982164bb3b099ed24e96cbe5589e
Sha1
ff087cc16eaf0c2b8581f4bb090c799aa51017a9
Sha256
48be2502fad84657b383c41b2616f34a029f9a39d63aae1a1714faf7ba79e3da
Sha384
939f2e8de2454f78d16b4a2d45d1d19805f01ad651c5cbdacbcff1549fba90f7ecad352a25313cc4bbd5680d548fa97b
Sha512
a1147045847b8a2a7759c0edf55dfd93dd54d58a4e84e87fa9b9c7ccaeaa44dd4d711cf1e6f739fb438122b7391c5b40d9285de1d0dbfdd9c86ccce29fef7d5d
SSDeep
24576:h2MaO8HhlrU2S0V3EzpDMKsMQCLiiVd7ngo/XEWuHtIy6dbkfOkPo4cwX7hDR8dh:3OBG1q3ETN97gjHuyROkglw10xy8RJd
TLSH
A8A5EFA1B043D227EF031C7C48AB5BBCA1BD5A9BBF3886091FA598ED8CEDF51560C541

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

ナrVl{qキ

Full Name

ナrVl{qキ

EntryPoint

System.Void VVは力?P4玉 MOナBpoルりB4R科丹サNSサ?大R&xd鶐伝伝Yサ$灯Y::S[A力 S*#|ル8学wIYzOBD]瑞鶐.(( 3はCjマ人oy!阪ァX 人(System.String[])

Scope Name

ナrVl{qキ

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

vBNJXOu7EZwi6j9

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

20

Main Method

System.Void VVは力?P4玉 MOナBpoルりB4R科丹サNSサ?大R&xd鶐伝伝Yサ$灯Y::S[A力 S*#|ル8学wIYzOBD]瑞鶐.(( 3はCjマ人oy!阪ァX 人(System.String[])

Main IL Instruction Count

18

Main IL

ldc.i4 6000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldsfld System.Byte[] 路キzLs瑞+;]ステ谷D8RT伝通a=rTRJ[CD +命X谷マ)宏Pィ人学@::y路Na宏;mCq_0y望.8}Ws-|HrZ通Hj通}w7@ァ@¥? qナ要Q call System.Byte[] ,bり市@$bv{*科1%qpwPa阪ャkサUFr宏]1sR伝ルsCY4#ルp6::QDャ+]}命9wスb¥克JRsay6EWfqS=s[@e-鎰A谷Ѫグ<Ѫbq:(System.Byte[]) stloc.0 <null> ldsfld System.String 路キzLs瑞+;]ステ谷D8RT伝通a=rTRJ[CD +命X谷マ)宏Pィ人学@::c?i鶐f7tWUJ灯RXキ)5fi丹Y要マP_ャ3P力{Zャ大ルi{nFHマQ ldloc.0 <null> call System.Void X;阪|Pvo科通阪!瑞}克3=HSϒ0Pァ9+.:b能?鎰x牡望GHナ#&市c::大^市_oサ!Wdm4ナ&kϒマ*iP]3bzマo0Cdm阪灯系スマ鎰Y要NI路(System.String,System.Byte[]) leave.s IL_002F: leave.s IL_0038 pop <null> leave.s IL_0038: ret leave.s IL_0038: ret ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) endfinally <null> ret <null>

Module Name

ナrVl{qキ

Full Name

ナrVl{qキ

EntryPoint

System.Void VVは力?P4玉 MOナBpoルりB4R科丹サNSサ?大R&xd鶐伝伝Yサ$灯Y::S[A力 S*#|ル8学wIYzOBD]瑞鶐.(( 3はCjマ人oy!阪ァX 人(System.String[])

Scope Name

ナrVl{qキ

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

vBNJXOu7EZwi6j9

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

20

Main Method

System.Void VVは力?P4玉 MOナBpoルりB4R科丹サNSサ?大R&xd鶐伝伝Yサ$灯Y::S[A力 S*#|ル8学wIYzOBD]瑞鶐.(( 3はCjマ人oy!阪ァX 人(System.String[])

Main IL Instruction Count

18

Main IL

ldc.i4 6000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldsfld System.Byte[] 路キzLs瑞+;]ステ谷D8RT伝通a=rTRJ[CD +命X谷マ)宏Pィ人学@::y路Na宏;mCq_0y望.8}Ws-|HrZ通Hj通}w7@ァ@¥? qナ要Q call System.Byte[] ,bり市@$bv{*科1%qpwPa阪ャkサUFr宏]1sR伝ルsCY4#ルp6::QDャ+]}命9wスb¥克JRsay6EWfqS=s[@e-鎰A谷Ѫグ<Ѫbq:(System.Byte[]) stloc.0 <null> ldsfld System.String 路キzLs瑞+;]ステ谷D8RT伝通a=rTRJ[CD +命X谷マ)宏Pィ人学@::c?i鶐f7tWUJ灯RXキ)5fi丹Y要マP_ャ3P力{Zャ大ルi{nFHマQ ldloc.0 <null> call System.Void X;阪|Pvo科通阪!瑞}克3=HSϒ0Pァ9+.:b能?鎰x牡望GHナ#&市c::大^市_oサ!Wdm4ナ&kϒマ*iP]3bzマo0Cdm阪灯系スマ鎰Y要NI路(System.String,System.Byte[]) leave.s IL_002F: leave.s IL_0038 pop <null> leave.s IL_0038: ret leave.s IL_0038: ret ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) endfinally <null> ret <null>

0e47982164bb3b099ed24e96cbe5589e (2.15 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙