Suspicious
Suspect

29c7dc51b83b85c888ea2263cc550753

PE Executable
|
MD5: 29c7dc51b83b85c888ea2263cc550753
|
Size: 304.28 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
29c7dc51b83b85c888ea2263cc550753
Sha1
354a31f721dd67db9e027bddd1457a3718241104
Sha256
808fdfb482f8fb4fe6fd40905a7868f279d797982093ee10e60267a27882f026
Sha384
8d78767557b99e84217f37fc46cd8b19989fd41e98d5d8e5d681663c3533d28bbb9c9a476efa1cf1f210387ddfcbd9a8
Sha512
d6b6a636d38a358eaec78b357c744bfda5ba08ebc65c4c087f5632914ad5db902858b5cb9d45c799e4361da2249dcf481b6800d719ad70fb4557c397e649a162
SSDeep
1536:NruETxV67h1nMrRxPEf5EJsslSbFyiR+R7BI/9nsVneYSb4A2tFVNZhBFZdBJjdW:wumwH9AGFvBJjdqgbpuXA96iibCW
TLSH
D354300EBE66846CCD54D732D45EF033F624AE81F24AE70AE5493FD638333A94A85536

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
[Authenticode]_e6906059.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ZetaLongPaths.Properties.Resources.resources
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x47C00 size 10392 bytes

Module Name

to-27.exe

Full Name

to-27.exe

EntryPoint

System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::SetResponder()

Scope Name

to-27.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

to-27

Assembly Version

142.0.7416.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

134

Main Method

System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::SetResponder()

Main IL Instruction Count

17

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0049: nop nop <null> call System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::MeasureResponder() ldc.i4 0 ldsfld <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b} <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b}::m_d2bd3190abdc45818cb62724d55ee73a ldfld System.Int32 <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b}::m_02e12a3b754a47ebade9d53e9d6ef838 brfalse IL_0012: switch(IL_0049,IL_0024) pop <null> ldc.i4 0 br IL_0012: switch(IL_0049,IL_0024) nop <null> ret <null>

Module Name

to-27.exe

Full Name

to-27.exe

EntryPoint

System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::SetResponder()

Scope Name

to-27.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

to-27

Assembly Version

142.0.7416.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

134

Main Method

System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::SetResponder()

Main IL Instruction Count

17

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0049: nop nop <null> call System.Void ZetaLongPaths.ResponseHandling.AdvancedResponder::MeasureResponder() ldc.i4 0 ldsfld <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b} <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b}::m_d2bd3190abdc45818cb62724d55ee73a ldfld System.Int32 <Module>{72d9162f-fc3b-4483-bb31-623b155e9e4b}::m_02e12a3b754a47ebade9d53e9d6ef838 brfalse IL_0012: switch(IL_0049,IL_0024) pop <null> ldc.i4 0 br IL_0012: switch(IL_0049,IL_0024) nop <null> ret <null>

29c7dc51b83b85c888ea2263cc550753 (304.28 KB)
File Structure
[Authenticode]_e6906059.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ZetaLongPaths.Properties.Resources.resources
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙