Suspicious
Suspect

1657ac909f8abcf171e6f282d3904205

PE Executable
|
MD5: 1657ac909f8abcf171e6f282d3904205
|
Size: 747.53 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
1657ac909f8abcf171e6f282d3904205
Sha1
0f1d22fb60a327c19a1acf6e382376aaedac25dd
Sha256
7b09cd99f77589db2c229244b7f5c5d8d53113155439b8c41963e36581f35e0c
Sha384
0a4079a16d18a47a046ddf30b5480505c18d977ac17f89626732ca78158cccb43e8f43eb124942746ce926da736fe140
Sha512
656629b02883db44b32e333878b1f2515547b473fef6c9327e49ae7d74d8b0dc06470dc894749c8c26d4030b30d9e4059e692c0142080617fba58f570c255a98
SSDeep
12288:/Nmq/NRijZ5lyk6Kg/M9b6CDh4xVcViONJsMKQ2qdOpjJEOy9kR:Vm6RijZjq4b6CV4YV1NJRJ2qdOlmQ
TLSH
1EF412002719EA03D66517B109B0F2741BBA7D96B820C35ADEDA7EEFBA76F144844B13

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
aAzs
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0xB3200 size 13832 bytes

Info

PDB Path: KSWf.pdb

Module Name

KSWf.exe

Full Name

KSWf.exe

EntryPoint

System.Void ModularExponentiation.Program::Main()

Scope Name

KSWf.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

KSWf

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

224

Main Method

System.Void ModularExponentiation.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ModularExponentiation.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

KSWf.exe

Full Name

KSWf.exe

EntryPoint

System.Void ModularExponentiation.Program::Main()

Scope Name

KSWf.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

KSWf

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

224

Main Method

System.Void ModularExponentiation.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ModularExponentiation.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

1657ac909f8abcf171e6f282d3904205 (747.53 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙