Suspicious
Suspect

101ef9a25691f0f674c0a08ac7770070

PE Executable
|
MD5: 101ef9a25691f0f674c0a08ac7770070
|
Size: 535.55 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
101ef9a25691f0f674c0a08ac7770070
Sha1
fb54cebc12174bafd88f0ef361d46b2911563545
Sha256
d78b1315a596c3424ed01722ea7d1370180affa97474a8a4fd55b1bb012c8411
Sha384
f437c48742a7f6d72e530851c35cb4bfdea78955e0623562a75445c654572d5fd5febb18f67ff8a7c55d5ebd274a4354
Sha512
528b4bbe0b907ab0a6004a0f56d9b714e344d5e5585996587e005435fa11ad6ec7594890c5fe227c8a9f389d35be460051b302426196f94ed90588d63f746a52
SSDeep
12288:qpqSX0PUjG/EqQHkbjbqEpWNHCn8DJ2eP14Sgkhan2:hZP6qQEbVgHCn8+
TLSH
B4B4015A2259D912D1FB2BB01CB0D3B893B96D897911E30A4FFABCDB7C217105A513E3

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConverter.Forms.MainForm.resources
UnitConverter.Properties.Resources.resources
hPOi
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: QtvJ.pdb

Module Name

QtvJ.exe

Full Name

QtvJ.exe

EntryPoint

System.Void UnitConverter.Program::Main()

Scope Name

QtvJ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

QtvJ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

400

Main Method

System.Void UnitConverter.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void UnitConverter.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

QtvJ.exe

Full Name

QtvJ.exe

EntryPoint

System.Void UnitConverter.Program::Main()

Scope Name

QtvJ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

QtvJ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

400

Main Method

System.Void UnitConverter.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void UnitConverter.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

101ef9a25691f0f674c0a08ac7770070 (535.55 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙