Suspicious
Suspect

151eb85cf454d5d00b52be7ff2d66ce0

PE Executable
|
MD5: 151eb85cf454d5d00b52be7ff2d66ce0
|
Size: 95.23 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
151eb85cf454d5d00b52be7ff2d66ce0
Sha1
1ae5709bd5c321fb77b20e3788e9bba5b7b9f382
Sha256
708833dcf6081052872aeb1e6119d69ba59863aefe56122115e3654656f11cdf
Sha384
985e4b0e4172becbd69de59114eddfd28216e38a0510f0aa4e7f642f129cf7e28be8b05e1e08058f66f4619af75bc9cc
Sha512
a0041208f7555e624e58f46b85739746faeef9962a8c9da4be40dad16757fe15f2bda73f7aee3d26d18726e3a92a697ee76cd918b7d7d37be2b0dad79dd6a809
SSDeep
1536:r/eNr7EkrjaFIs7E5OxFJn8LjEwzGi1dDmDngS:r/eRjau5O/Vni1dYg
TLSH
1893C74977E56564E0BF56F79871F2004E34B48B1602E39D48F259AB0B33AC44F89FEA

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Stub.exe

Full Name

Stub.exe

EntryPoint

System.Void Stub.A::main()

Scope Name

Stub.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Stub

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1272

Main Method

System.Void Stub.A::main()

Main IL Instruction Count

25

Main IL

nop <null> ldc.i4.1 <null> stsfld System.Boolean Stub.A::runx ldnull <null> ldftn System.Void Stub.A::timx_run() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) stsfld System.Threading.Thread Stub.A::thx ldsfld System.Threading.Thread Stub.A::thx callvirt System.Void System.Threading.Thread::Start() nop <null> ldc.i4.1 <null> stsfld System.Boolean Stub.A::runy ldnull <null> ldftn System.Void Stub.A::timy_run() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) stsfld System.Threading.Thread Stub.A::thy ldsfld System.Threading.Thread Stub.A::thy callvirt System.Void System.Threading.Thread::Start() nop <null> call System.Void Stub.Fransesco::ko() nop <null> nop <null> ret <null>

Module Name

Stub.exe

Full Name

Stub.exe

EntryPoint

System.Void Stub.A::main()

Scope Name

Stub.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Stub

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1272

Main Method

System.Void Stub.A::main()

Main IL Instruction Count

25

Main IL

nop <null> ldc.i4.1 <null> stsfld System.Boolean Stub.A::runx ldnull <null> ldftn System.Void Stub.A::timx_run() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) stsfld System.Threading.Thread Stub.A::thx ldsfld System.Threading.Thread Stub.A::thx callvirt System.Void System.Threading.Thread::Start() nop <null> ldc.i4.1 <null> stsfld System.Boolean Stub.A::runy ldnull <null> ldftn System.Void Stub.A::timy_run() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) stsfld System.Threading.Thread Stub.A::thy ldsfld System.Threading.Thread Stub.A::thy callvirt System.Void System.Threading.Thread::Start() nop <null> call System.Void Stub.Fransesco::ko() nop <null> nop <null> ret <null>

151eb85cf454d5d00b52be7ff2d66ce0 (95.23 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙