Suspicious
Suspect

29d1e00c4ab770ce9aa673a9f4a14e4d

PE Executable
|
MD5: 29d1e00c4ab770ce9aa673a9f4a14e4d
|
Size: 5.59 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
29d1e00c4ab770ce9aa673a9f4a14e4d
Sha1
8698081b0bae9d59f64bd53a5dfbceef355f744c
Sha256
f15e14ebf36994b97276ac49f84df973623a313489a1a9e86bd4e30feb225fad
Sha384
ff48cc03b535b97b25e5427723032d1797b09b872adf7e65e8321c9d51191069ff76d40b40eb3d40e70891c81abbf9e0
Sha512
ef24f2339d1a8dfb7190aa1ff6660450db868847064ea064d821e7496b87208575d5e1acf91cc0445e745d2a3f4c0b3cba41f6517e759816f26d7fb68b6273f7
SSDeep
49152:E18eP3T1qu8VviNVf9M7pDEYmy1JBrbF1iCm6B6:E7PJqu8VviNVf9wpDEYLrbF1i
TLSH
DD460828A4A5E703E50C077BC0F8493492640E356E6BCB67DE91443EE6B17FD0E5DB8A

PeID

Microsoft Visual C++ v6.0 DLL
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Microsoft.Win32.TaskScheduler.Properties.Resources.resources
Microsoft.Win32.TaskScheduler.TaskService.bmp
xlAp
dDnv
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Microsoft.Win32.TaskScheduler.dll

Full Name

Microsoft.Win32.TaskScheduler.dll

Scope Name

Microsoft.Win32.TaskScheduler.dll

Scope Type

ModuleDef

Kind

Dll

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Microsoft.Win32.TaskScheduler

Assembly Version

2.11.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

52

Main Method

Not found or no body

29d1e00c4ab770ce9aa673a9f4a14e4d (5.59 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Microsoft.Win32.TaskScheduler.Properties.Resources.resources
Microsoft.Win32.TaskScheduler.TaskService.bmp
xlAp
dDnv
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙