Suspicious
Suspect

27d38fbe57739aa189995cc0d13ddc49

PE Executable
|
MD5: 27d38fbe57739aa189995cc0d13ddc49
|
Size: 818.7 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
27d38fbe57739aa189995cc0d13ddc49
Sha1
32f27057262ff6bac30beda5ff6e70e9ee83872f
Sha256
272fbf9d620d1c0f1b2a0bb224709516ec9e5d5874807588f363451f8a2df268
Sha384
56102bdd1f04fa299da65c814cc349f9f32341eabad3c1af41d547c594ba720f404404329f1f333dae991659240b9e4d
Sha512
3745694e9d41f96213935d116ec151c06a8e5a0c44faa91218735a894542956975beee463d600fbd15778c8ab681087bfc8c71dfeae8a8ad2dbd2bf92b283cf8
SSDeep
12288:EeirX/VyPZrICIXm/Xuejv8T1Eu2gjH04IJsLStAPh1eW7mkR:EF/Vi8CIXm/XFjv8mxALn3eWB
TLSH
0B05F044D604E002C55D3E7C19B0CFBB5D6ADE99A82CF2D2BAECBCA73736AC514D8081

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
XvlK
[NBF]root.Data
[NBF]root.Data-preview.png
htta
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0xC4800 size 13832 bytes

Info

PDB Path: RncS.pdb

Module Name

RncS.exe

Full Name

RncS.exe

EntryPoint

System.Void SmartNotesApp.Program::Main()

Scope Name

RncS.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

RncS

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

76

Main Method

System.Void SmartNotesApp.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void SmartNotesApp.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

RncS.exe

Full Name

RncS.exe

EntryPoint

System.Void SmartNotesApp.Program::Main()

Scope Name

RncS.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

RncS

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

76

Main Method

System.Void SmartNotesApp.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void SmartNotesApp.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

27d38fbe57739aa189995cc0d13ddc49 (818.7 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙