Suspicious
Suspect

216d197ded075e2c6271822f08ee8370

PE Executable
|
MD5: 216d197ded075e2c6271822f08ee8370
|
Size: 3.92 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
216d197ded075e2c6271822f08ee8370
Sha1
3eebf00b8358178611cbd37f50eb27adf4a5dd53
Sha256
cbd6d67b967edef057f41ff0a516e827d9b3ad4d99a1ecc1b75e7fa9363101e9
Sha384
e30b08e10d1a18e072dbed07c2c3d5e2e370cae262d6234cc08b9456137bb0a8f6b0816136f2aabdef22fd92db8ce671
Sha512
7854273fa5baae5210ee365156b9ae38207bdd8b9825d412577739e4015223b5541b8f583a86f2e35362c93a0ff7af36fe98172b8a67a8afc439476bd8767c7d
SSDeep
98304:ij7FTbmRyQ5fuj+3b6xFhLM8108EiGAUB4FIOZU:iHJyVp7bchgnfaIaU
TLSH
EF063304269BEA53C4332BF416A1E6B45BF40EC82421F6034FD72EEFBE29B455E516E4

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YahtzeeClone.FormGioco.resources
WindowsFormsApp2.Properties.Resources.resources
VY
[NBF]root.Data
image_516
[NBF]root.Data
[NBF]root.Data-preview.png
rwWWd
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: QbnPE.pdb

Module Name

QbnPE.exe

Full Name

QbnPE.exe

EntryPoint

System.Void WindowsFormsApp2.Program::Main()

Scope Name

QbnPE.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

QbnPE

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

262

Main Method

System.Void WindowsFormsApp2.Program::Main()

Main IL Instruction Count

11

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldstr x newobj System.Void YahtzeeClone.FormGioco::.ctor(System.String) call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

QbnPE.exe

Full Name

QbnPE.exe

EntryPoint

System.Void WindowsFormsApp2.Program::Main()

Scope Name

QbnPE.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

QbnPE

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

262

Main Method

System.Void WindowsFormsApp2.Program::Main()

Main IL Instruction Count

11

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldstr x newobj System.Void YahtzeeClone.FormGioco::.ctor(System.String) call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

216d197ded075e2c6271822f08ee8370 (3.92 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙