Suspicious
Suspect

2b3fa95cb00e0cc7d60a7515e1affa52

PE Executable
|
MD5: 2b3fa95cb00e0cc7d60a7515e1affa52
|
Size: 15.39 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
2b3fa95cb00e0cc7d60a7515e1affa52
Sha1
95ea527c0c8766109eed73a1b3a0e67fb6999655
Sha256
b8f664bb33570ef296d2dac59e04735830af97de464d546843045b2cf4d62741
Sha384
3923b44acc7bcbc99cf322157dabe83bc1491908bd784bfaf5a7d15f2c9e6868bb7c986d6b8e61bdcc5766c5a097e588
Sha512
d1bbcd8c7133f69756b953f4250da266458b769f1ccbbc36b87788743f23e1cd8734a750046f4e6c85b35b898101e5fe6f234800e566c966a54237f1bde41cda
SSDeep
196608:00c1TnWqBGXav8jdReU5rE6PiJzKV977JITKjFRjeIrk2+YLFF1FSm/vo:0xnpQ68ZEU5rEhW9jrjeaP5F10mX
TLSH
F6F6172010D96607FD3EEFBD85DCB6444F7AB2953727EA389B410DE90BD1B08C9429A7

PeID

Microsoft Visual C++ DLL
Microsoft Visual C++ v6.0
Microsoft Visual C++ v6.0 DLL
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
outcome.Properties.Resources.resources
El
XDC
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Debug\main\obj\Debug\anxiety3469.pdb

Module Name

anxiety3469.exe

Full Name

anxiety3469.exe

EntryPoint

System.Void outcome.Program::Main()

Scope Name

anxiety3469.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

anxiety3469

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5.2

Total Strings

81558

Main Method

System.Void outcome.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void outcome.dar1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

2b3fa95cb00e0cc7d60a7515e1affa52 (15.39 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙