Suspicious
Suspect

158c2a1cbdc3f8c4e667d4539ff9b30a

PE Executable
|
MD5: 158c2a1cbdc3f8c4e667d4539ff9b30a
|
Size: 765.95 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
158c2a1cbdc3f8c4e667d4539ff9b30a
Sha1
89dd6a64c3325f979247b99077ebf1997a5ba48d
Sha256
d1dac84e05c1f6d563953e4966b4a15dda5ad228298cb9ffaa904108a1e03409
Sha384
cf125b372802847a1aad33ecd9cba03097a4804f053feb0d123ce69a014e57bed009a7a1534b3cd639433bbf6eea52a7
Sha512
dc40d9bcd757e97d971580c990f384dd3eb203bfd7b3ab747ca86fc52c8af46f96182e5dd8bc12cfcef6710e925a860cabe48d0bfd2771109de06f5b4a2b503d
SSDeep
12288:SWZ0Lpr9YtQZZzdCJvkx4uDsBVzlaDSNd7GPbv1b9iTQgm2CaVYzccLdpH:OdZZzdCJvkYzllNkPbdb9tV2Ckwc0
TLSH
76F4BE2823E85A08F5FF1B39697415144BF1FC26DA32EA1E6EA650DE0E65F80DD60733

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
kTb6td1E3c.g.resources
kTb6td1E3c.Resources.resources
cd143fbbcc81c7.Resources.resources
06ba19030
[NBF]root.Data
06ba19031
[NBF]root.Data
06ba19032
[NBF]root.Data
06ba19033
[NBF]root.Data
06ba19034
[NBF]root.Data
06ba19035
[NBF]root.Data
06ba19036
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

kTb6td1E3c

Full Name

kTb6td1E3c

EntryPoint

System.Void kTb6td1E3c.Ny5f3DzjcxX9L/Gsi69xHjmB2.5NobZw0s7::6nrWkQb0B5gy()

Scope Name

kTb6td1E3c

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

kTb6td1E3c

Assembly Version

1.19.35.96

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void kTb6td1E3c.Ny5f3DzjcxX9L/Gsi69xHjmB2.5NobZw0s7::6nrWkQb0B5gy()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void kTb6td1E3c.ir5A3eZnk4pM::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

kTb6td1E3c

Full Name

kTb6td1E3c

EntryPoint

System.Void kTb6td1E3c.Ny5f3DzjcxX9L/Gsi69xHjmB2.5NobZw0s7::6nrWkQb0B5gy()

Scope Name

kTb6td1E3c

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

kTb6td1E3c

Assembly Version

1.19.35.96

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void kTb6td1E3c.Ny5f3DzjcxX9L/Gsi69xHjmB2.5NobZw0s7::6nrWkQb0B5gy()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void kTb6td1E3c.ir5A3eZnk4pM::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

158c2a1cbdc3f8c4e667d4539ff9b30a (765.95 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙