Suspicious
Suspect

184f8aa486fe05a6d49d6b9595350ffa

PE Executable
|
MD5: 184f8aa486fe05a6d49d6b9595350ffa
|
Size: 1.09 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
184f8aa486fe05a6d49d6b9595350ffa
Sha1
d4c7682d7efdbd935b285280da26764696edc282
Sha256
c516363e147f458e1806ace3348ded638bfdeef92c663a2478940e45b95cb911
Sha384
5f3dc656011c4bcc9c6549af2abb698508db19f215c6fe72d2ba3f298c7b928c8f9f79cba5e3435a4907a0943fdcb916
Sha512
028504f395c3c5df0108c11d93dbfaf7b3649357491ccd82557c0e467cfec36cbf3610f99a3ac2755868c6b0090faa07b8e6cecb835c7ad1fb45bbdf912ba554
SSDeep
24576:qG3wsNr9oqgAVXTT9SWEJdKspdrXdn5b8YE0C4oBjLDLguQlVict:qps19oqgIAJdD7rXbhYBnDUuWQc
TLSH
42350264A26ED962C2980B7780E2D77403B48E96E553C3771ECA6FF77A57B930990303

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NImRL.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
MindPalace.Properties.Resources.resources
eIxRX
[NBF]root.Data
[NBF]root.Data-preview.png
Clear
[NBF]root.Data
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: NImRL.pdb

Module Name

NImRL.exe

Full Name

NImRL.exe

EntryPoint

System.Void xo6.hom::Oo2()

Scope Name

NImRL.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NImRL

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

210

Main Method

System.Void xo6.hom::Oo2()

Main IL Instruction Count

50

Main IL

br IL_00A0: nop nop <null> ret <null> call System.Void yyR.xyw::LLz() br IL_00AB: nop nop <null> nop <null> call System.String Xb4.Kbq::CoR() call Xb4.Kbq Xb4.Kbq::MbD(System.String) call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_0042: nop ldloc.s V_0 brfalse IL_005D: nop br IL_0033: call Xb4.Kbq Xb4.Kbq::CbG() call Xb4.Kbq Xb4.Kbq::CbG() call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_005C: nop nop <null> call Xb4.Kbq xo6.hom::doi() callvirt System.Collections.Generic.List`1<tjK.mjJ> Xb4.Kbq::Hb0() callvirt System.Int32 System.Collections.Generic.List`1<tjK.mjJ>::get_Count() ldc.i4.0 <null> ceq <null> stloc.s V_0 br IL_0027: ldloc.s V_0 nop <null> nop <null> leave IL_0085: newobj System.Void NoU.eo5::.ctor() pop <null> br IL_0069: nop nop <null> call Xb4.Kbq Xb4.Kbq::CbG() call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_0079: nop nop <null> nop <null> leave IL_0085: newobj System.Void NoU.eo5::.ctor() br IL_0085: newobj System.Void NoU.eo5::.ctor() newobj System.Void NoU.eo5::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0005: nop nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_0007: call System.Void yyR.xyw::LLz() nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0094: nop nop <null> br IL_0011: nop

Module Name

NImRL.exe

Full Name

NImRL.exe

EntryPoint

System.Void xo6.hom::Oo2()

Scope Name

NImRL.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NImRL

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

210

Main Method

System.Void xo6.hom::Oo2()

Main IL Instruction Count

50

Main IL

br IL_00A0: nop nop <null> ret <null> call System.Void yyR.xyw::LLz() br IL_00AB: nop nop <null> nop <null> call System.String Xb4.Kbq::CoR() call Xb4.Kbq Xb4.Kbq::MbD(System.String) call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_0042: nop ldloc.s V_0 brfalse IL_005D: nop br IL_0033: call Xb4.Kbq Xb4.Kbq::CbG() call Xb4.Kbq Xb4.Kbq::CbG() call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_005C: nop nop <null> call Xb4.Kbq xo6.hom::doi() callvirt System.Collections.Generic.List`1<tjK.mjJ> Xb4.Kbq::Hb0() callvirt System.Int32 System.Collections.Generic.List`1<tjK.mjJ>::get_Count() ldc.i4.0 <null> ceq <null> stloc.s V_0 br IL_0027: ldloc.s V_0 nop <null> nop <null> leave IL_0085: newobj System.Void NoU.eo5::.ctor() pop <null> br IL_0069: nop nop <null> call Xb4.Kbq Xb4.Kbq::CbG() call System.Void xo6.hom::DoF(Xb4.Kbq) br IL_0079: nop nop <null> nop <null> leave IL_0085: newobj System.Void NoU.eo5::.ctor() br IL_0085: newobj System.Void NoU.eo5::.ctor() newobj System.Void NoU.eo5::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0005: nop nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_0007: call System.Void yyR.xyw::LLz() nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0094: nop nop <null> br IL_0011: nop

184f8aa486fe05a6d49d6b9595350ffa (1.09 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙