Suspicious
Suspect

26fbd426c1d57d9515b50d11a319f8f6

PE Executable
|
MD5: 26fbd426c1d57d9515b50d11a319f8f6
|
Size: 696.32 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
26fbd426c1d57d9515b50d11a319f8f6
Sha1
e29707f48b06047d4b52806723a75266bb2f6b83
Sha256
19a3283949271cf9f779d7d9377ad322e6fd1b06d169f9b041e09db28a7fed18
Sha384
d8fb01f05a3ae5ce396771eab401de82f8681ddeb0e9b4aad7d7aa1d947af38a040c1f379162186c2f136fcfe804069e
Sha512
98d4bbad3c959a8281173d8dc8ea18b4d9015d45b5f4481af43e361ba52ccef62d63d9369e688a6cb0dc09ffba6603e3a3f7f1ebb240b973885272b434a22872
SSDeep
12288:bKXB4IUAO+ZwE/bsuWuLtMwLne5fP49VoptFPSKuZTJ2MIwG:bmAfssduhMSne5EPiM
TLSH
8EE4236DBF728B7AC94C1B3BE8A34A0244F94A45E131FB9B089A4BF10F18796D5C5523

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

tZWo.exe

Full Name

tZWo.exe

EntryPoint

System.Void SolarSystem.Program::Main()

Scope Name

tZWo.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

tZWo

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void SolarSystem.Program::Main()

Main IL Instruction Count

27

Main IL

ldsfld System.Int32[] SolarSystem.Properties.Resources::Ⴐ stloc.2 <null> ldc.i4.2 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void gar3t.LucidIoC.Configuration::Ⴈ() ldc.i4 494 ldc.i4 446 call System.Void SolarSystem.Form1::Ⴃ(System.Char,System.Int32) ldc.i4.0 <null> ldc.i4 1012 ldc.i4 967 call System.Void SolarSystem.Program::Ⴄ(System.Boolean,System.Int32,System.Int16) ldloc.2 <null> ldc.i4 234 ldelem.i4 <null> ldc.i4 11885 sub <null> stloc.1 <null> br.s IL_0008: ldloc.1 newobj System.Void SolarSystem.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void SolarSystem.Program::Main() pop <null> ret <null>

Module Name

tZWo.exe

Full Name

tZWo.exe

EntryPoint

System.Void SolarSystem.Program::Main()

Scope Name

tZWo.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

tZWo

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void SolarSystem.Program::Main()

Main IL Instruction Count

27

Main IL

ldsfld System.Int32[] SolarSystem.Properties.Resources::Ⴐ stloc.2 <null> ldc.i4.2 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void gar3t.LucidIoC.Configuration::Ⴈ() ldc.i4 494 ldc.i4 446 call System.Void SolarSystem.Form1::Ⴃ(System.Char,System.Int32) ldc.i4.0 <null> ldc.i4 1012 ldc.i4 967 call System.Void SolarSystem.Program::Ⴄ(System.Boolean,System.Int32,System.Int16) ldloc.2 <null> ldc.i4 234 ldelem.i4 <null> ldc.i4 11885 sub <null> stloc.1 <null> br.s IL_0008: ldloc.1 newobj System.Void SolarSystem.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void SolarSystem.Program::Main() pop <null> ret <null>

26fbd426c1d57d9515b50d11a319f8f6 (696.32 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙