Suspicious
Suspect

1f6765eaa07a6276f77dcab1b20f4f1a

PE Executable
|
MD5: 1f6765eaa07a6276f77dcab1b20f4f1a
|
Size: 74.75 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
1f6765eaa07a6276f77dcab1b20f4f1a
Sha1
3224387a003896a7dac654a5ff7d5473f4266a84
Sha256
b2f6f559bb6c077f7a3dbe2fb5e3bbe6aa060391265fe8f719f45e9f2ce212cd
Sha384
cbc5d1469e9dc7dba83ff4fd6b091d5eeeb7c8596949d035a7a5b49ae71e4cd27fc3b97a3b869821c6b91f919d3246c8
Sha512
0544fa9c405ceb9d990fc00823d42356747511258e292b707a2f88bf96d9ad389ede11b46f7ea60134b17ebdda9387f1d8faf4f3c2d2b22d2c5719194a239431
SSDeep
1536:ktsPIBXI/BERtyqa8gNkaGcm60yW3NtlTbCAQZbWmjg:ktc/BEba8w17MYAQZbWmjg
TLSH
75731EDC725072EFC85BC4729EA82DA8FA6174BB831F4217942715ADAE4C897CF540F2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
!r:7 
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

SimpleRunPE.exe

Full Name

SimpleRunPE.exe

EntryPoint

System.Void ‮‏‍‎‎‏‬‮‍‮‫‏​​‫‍‍‪‭‬‌‭‌‬‌‮::‫‭‬​‮​‎‏‪‮‪‎‫‪‎‪‍​‭‌​‫​‪‎‪‭‮(System.String[])

Scope Name

SimpleRunPE.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SimpleRunPE

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

1

Main Method

System.Void ‮‏‍‎‎‏‬‮‍‮‫‏​​‫‍‍‪‭‬‌‭‌‬‌‮::‫‭‬​‮​‎‏‪‮‪‎‫‪‎‪‍​‭‌​‫​‪‎‪‭‮(System.String[])

Main IL Instruction Count

0

Main IL

1f6765eaa07a6276f77dcab1b20f4f1a (74.75 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
!r:7 
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙