Suspicious
Suspect

19e577db17394e0c8888a3d882c2c432

PE Executable
|
MD5: 19e577db17394e0c8888a3d882c2c432
|
Size: 875.01 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
19e577db17394e0c8888a3d882c2c432
Sha1
c62b6c3b76a254f7518b47e53b2c93b2f375360c
Sha256
a1c44bbae92cfe93be55c8fc0b950b96b238ef92fac6fed6f32157161d8cc573
Sha384
43a6349a80730450a9ceb81f4757b3b05b2516fae4b403341e6d18b52e673c7422f533da4577fe70562bd888d3a6f3e6
Sha512
8bc2e1c6fe79ea06f573efde2b7493f1fbbdfe6d06410fae526e22ca43f56a5f039d71178ee0eb9f3b0259be0d9d1538fb38a9b77b40a0a4022482e5604fd9b6
SSDeep
12288:y1eW7CyQHy+S6KqIV41dsUlHNGJZp4Hds2tcMbk43m/9Tb:KeWOfH/Sfu1dPJQJZiHi2GUq/
TLSH
711502542607DBD6C0D107FC59B1EF78127B0E886851DF3E5ADDBEEB3B2A6081D80A25
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
XjaD
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: wBJJ.pdb

Module Name

wBJJ.exe

Full Name

wBJJ.exe

EntryPoint

System.Void ticTacToe.Program::Main()

Scope Name

wBJJ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

wBJJ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

155

Main Method

System.Void ticTacToe.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ticTacToe.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

19e577db17394e0c8888a3d882c2c432 (875.01 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
XjaD
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙