Suspicious
Suspect

2a8f9daf4bd4127b417107f002970a55

PE Executable
|
MD5: 2a8f9daf4bd4127b417107f002970a55
|
Size: 735.23 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
2a8f9daf4bd4127b417107f002970a55
Sha1
0b85b3654d9afbd5e067be46a26699fa89581c7f
Sha256
0c0178a5a900d81323de41c3f4c957760b3b0c799718213a235b976fbb2f5221
Sha384
8b7bbc26b665460bf29ae2cd2d668a73938dab9a0037b4748028a56b6a2d65c20bff078f336421b5a991d28d1f7ff698
Sha512
8bc34afd75e96d5ac1ed782442292e284e3b792245f2d1ccc14ff540853df3e5c54d807f11f1c8dd08521451910045eff811af1e3571adf05ba622bf3d5a13cf
SSDeep
12288:T73L/rb8Wk92mTqulnCRraPdLTDPhJjYthLUyNWpNU1kdtqNOFy+xPFszNva/f/a:v7v+bTqLVaxTbhJYttYvA+tkV03
TLSH
CEF412181B0EEE13D6E51BB45560E3B622749D48E906C2134FFDFDEBB429F81281D2A2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
EGCF
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ?

Module Name

eVWh.exe

Full Name

eVWh.exe

EntryPoint

System.Void oiMundo.Program::Main()

Scope Name

eVWh.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eVWh

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

161

Main Method

System.Void oiMundo.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void oiMundo.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

2a8f9daf4bd4127b417107f002970a55 (735.23 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙