Suspicious
Suspect

2869ce3d82bc1c8d9b707992bc176b93

PE Executable
|
MD5: 2869ce3d82bc1c8d9b707992bc176b93
|
Size: 902.66 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
2869ce3d82bc1c8d9b707992bc176b93
Sha1
73389e75cba4460d86e859fc419b4c6cd2e80bca
Sha256
5430d9faf55e36dfc17034194780f1abbad5f5670f63ac3c1870da3352e2f342
Sha384
f84dbc927b96575cb924206697560f602f00b9c5e76e9f5719b814243941c11dd2c4ec79c81e5ea2058c2ee81b76c88c
Sha512
3ab1b0b463bf78e2afdab1a24f45d51269a9d0b550d76d8fd54b97c2495125d27017c65c5dd4241d51966fd30b37f2ab39335c8323e8074a31089d6f956c5354
SSDeep
12288:Zg4eclNQqGmoZejAXfCV4nv5nFmsZC/aOf3qK5vCKLZvyFXsyffX8PU/+pfhoJ7p:s8884JIVam0svm8yHip8tE7k
TLSH
42151244A7B9DFA2D8B90BF84560E77203BA6D8E9811C3134DCEBCF378A671029655D3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
VirtualWrapper.MainForm.resources
VirtualWrapper.Properties.Resources.resources
k0
mcOxq
Informations
Name
Value
Module Name

OfFDD.exe

Full Name

OfFDD.exe

EntryPoint

System.Void VirtualWrapper.Program::Main()

Scope Name

OfFDD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OfFDD

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

650

Main Method

System.Void VirtualWrapper.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void VirtualWrapper.Program::InitializeApplication() nop <null> newobj System.Void VirtualWrapper.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

OfFDD.exe

Full Name

OfFDD.exe

EntryPoint

System.Void VirtualWrapper.Program::Main()

Scope Name

OfFDD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OfFDD

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

650

Main Method

System.Void VirtualWrapper.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void VirtualWrapper.Program::InitializeApplication() nop <null> newobj System.Void VirtualWrapper.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

9

Suspicious Type Names (1-2 chars)

0

2869ce3d82bc1c8d9b707992bc176b93 (902.66 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙