Suspicious
Suspect

31f7ec7934d2d9c079be2b970008b0ea

PE Executable
|
MD5: 31f7ec7934d2d9c079be2b970008b0ea
|
Size: 1.11 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
31f7ec7934d2d9c079be2b970008b0ea
Sha1
52cba3b772f8c05a214c92de9612b7eec8418e51
Sha256
355aa161c72b5304e44d72065302f397d266d2fab77684bfb0ca47f68425fe8e
Sha384
e8ada73e90d44200fa4dc2307402c9076184a748f9ed9c247d9937a5dbfc0d37a162b47c5e21df55763fae5be8fd3da8
Sha512
cac320664c3bc9b35e6fb82ac0d05cc4bbd5b6ac3a94e29cfb8a259a6f576f7c2787079d0c10304f45ef607aa1ac27861315e34b5cede90afafa80a045b1691d
SSDeep
24576:Zo6R8r/edIW6kEFV+zkP4cewd3ByL5UOuFcBAfE+8y:Z8/rW6kSgixFd33OuFcK8y
TLSH
103502942268EE07D47E57F80435D2B253B56E05B132D3035ECB6DDBBDAAB602A14BC3
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Tetris.HighScoresTable.resources
$this.Icon
[NBF]root.IconData
Tetris.Properties.Resources.resources
PRIt
[NBF]root.Data
[NBF]root.Data-preview.png
eng_flag
[NBF]root.Data
[NBF]root.Data-preview.png
rus_flag
[NBF]root.Data
[NBF]root.Data-preview.png
Tetris.Tetris.resources
DrawTimer.TrayLocation
GameOverTimer.TrayLocation
TimerGameFunc.TrayLocation
plus
[NBF]root.Data
Informations
Name
Value
Module Name

lBYF.exe

Full Name

lBYF.exe

EntryPoint

System.Void Tetris.Program::Main()

Scope Name

lBYF.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

lBYF

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

340

Main Method

System.Void Tetris.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Tetris.Tetris::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
PDB Path

C:\Users\Administrator\Desktop\Client\Temp\SYhbDmoQYL\src\obj\Debug\lBYF.pdb

Embedded Resources

6

Suspicious Type Names (1-2 chars)

0

31f7ec7934d2d9c079be2b970008b0ea (1.11 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Tetris.HighScoresTable.resources
$this.Icon
[NBF]root.IconData
Tetris.Properties.Resources.resources
PRIt
[NBF]root.Data
[NBF]root.Data-preview.png
eng_flag
[NBF]root.Data
[NBF]root.Data-preview.png
rus_flag
[NBF]root.Data
[NBF]root.Data-preview.png
Tetris.Tetris.resources
DrawTimer.TrayLocation
GameOverTimer.TrayLocation
TimerGameFunc.TrayLocation
plus
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

C:\Users\Administrator\Desktop\Client\Temp\SYhbDmoQYL\src\obj\Debug\lBYF.pdb

31f7ec7934d2d9c079be2b970008b0ea

Embedded Resources

6

31f7ec7934d2d9c079be2b970008b0ea

Suspicious Type Names (1-2 chars)

0

31f7ec7934d2d9c079be2b970008b0ea

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙