Suspicious
Suspect

3242964b93864dc993de384b67e000d7

PE Executable
|
MD5: 3242964b93864dc993de384b67e000d7
|
Size: 747.01 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
3242964b93864dc993de384b67e000d7
Sha1
2b67aa307b5bf67d62d90c0edc455d2d9b934af1
Sha256
275696fd221a3a3e6d1e8f367ab648d42734bfc4e2deacf8824aeca6546b74bd
Sha384
a4de29ab1273539206f6221b1408659f5a191494e731a12f1d35c36e6eab60f58d66906144b72121e5f0833da7531d51
Sha512
9d464e743987400a00ffc6a23afc2aa2e563c713bcde3ec33b55791166e5813754cca5b6a23770f8697b4b2fa0fbbfee24b6a9b55b5c677e7a732d385e3847be
SSDeep
12288:vBCIb16qzL4yoP8kAsfZVUMtY3odZGvv/Zqifa0ApD46gt9Xzumaa:v8Ib16+fs7UNkZ/oLGsvthZ
TLSH
F0F4BE299E82AF41CABE1B79C092481833F0E4539266E71A3FF901F51FA3BD5DD13952

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Defobal.kerlaixo.odt
Kk8jtJj0G3.Resources.resources
6eb02883060603.Resources.resources
6a91e26a0
[NBF]root.Data
6a91e26a1
[NBF]root.Data
6a91e26a2
[NBF]root.Data
6a91e26a3
[NBF]root.Data
6a91e26a4
[NBF]root.Data
6a91e26a5
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Kk8jtJj0G3

Full Name

Kk8jtJj0G3

EntryPoint

System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37()

Scope Name

Kk8jtJj0G3

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Kk8jtJj0G3

Assembly Version

14.25.38.48

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37()

Main IL Instruction Count

112

Main IL

nop <null> br.s IL_0003: ldc.i4.8 ldc.i4.8 <null> stloc.s V_10 ldloc.s V_10 switch dnlib.DotNet.Emit.Instruction[] br.s IL_003F: nop nop <null> newobj System.Void Microsoft.VisualBasic.ApplicationServices.User::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.3 <null> stloc.2 <null> ldc.i4.s 20 stloc.3 <null> ldc.i4.7 <null> stloc.s V_10 br.s IL_0006: ldloc.s V_10 newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.s V_4 ldloc.3 <null> stloc.s V_6 ldc.i4.1 <null> stloc.s V_7 ldc.i4.s 9 stloc.s V_10 br.s IL_0006: ldloc.s V_10 ldloc.s V_4 ldloc.s V_7 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_7 ldc.i4.1 <null> add.ovf <null> stloc.s V_7 ldc.i4.s 9 stloc.s V_10 br IL_0006: ldloc.s V_10 ldloc.s V_7 ldloc.s V_6 ble.s IL_0096: ldc.i4.2 ldc.i4.5 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 ldc.i4.2 <null> br.s IL_008F: stloc.s V_10 ldloc.s V_4 callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.3 <null> ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_8 ldloc.s V_8 brfalse.s IL_00B4: ldc.i4.1 ldc.i4.6 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 ldc.i4.1 <null> br.s IL_00AD: stloc.s V_10 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> ldc.i4.1 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 nop <null> newobj System.Void System.Windows.Forms.PrintPreviewDialog::.ctor() stloc.s V_5 ldloc.s V_5 ldnull <null> callvirt System.Void System.Windows.Forms.PrintPreviewDialog::set_Document(System.Drawing.Printing.PrintDocument) nop <null> ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.3 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 nop <null> ldc.i4.6 <null> ldc.i4.s 11 ldnull <null> ldc.i4 460434636 call System.String Jpt5e4j.Ha9sdq/Fca2f0Krcq.Rex3je8WP::rW_0Ke7xo5GkaC(System.Int32,System.Int32,Jpt5e4j.Ha9sdq/Fca2f0Krcq.Rex3je8WP,System.Int32) call System.Void 5esCa1.1Knsof::Got0g(System.String) nop <null> leave.s IL_0117: br.s IL_0119 br.s IL_0101: br.s IL_0103 br.s IL_0103: call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0117: br.s IL_0119 br.s IL_0119: ldc.i4.4 ldc.i4.4 <null> stloc.s V_12 ldloc.s V_12 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0139: nop nop <null> ret <null> ldtoken System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37() pop <null> ret <null>

Module Name

Kk8jtJj0G3

Full Name

Kk8jtJj0G3

EntryPoint

System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37()

Scope Name

Kk8jtJj0G3

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Kk8jtJj0G3

Assembly Version

14.25.38.48

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37()

Main IL Instruction Count

112

Main IL

nop <null> br.s IL_0003: ldc.i4.8 ldc.i4.8 <null> stloc.s V_10 ldloc.s V_10 switch dnlib.DotNet.Emit.Instruction[] br.s IL_003F: nop nop <null> newobj System.Void Microsoft.VisualBasic.ApplicationServices.User::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.3 <null> stloc.2 <null> ldc.i4.s 20 stloc.3 <null> ldc.i4.7 <null> stloc.s V_10 br.s IL_0006: ldloc.s V_10 newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.s V_4 ldloc.3 <null> stloc.s V_6 ldc.i4.1 <null> stloc.s V_7 ldc.i4.s 9 stloc.s V_10 br.s IL_0006: ldloc.s V_10 ldloc.s V_4 ldloc.s V_7 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_7 ldc.i4.1 <null> add.ovf <null> stloc.s V_7 ldc.i4.s 9 stloc.s V_10 br IL_0006: ldloc.s V_10 ldloc.s V_7 ldloc.s V_6 ble.s IL_0096: ldc.i4.2 ldc.i4.5 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 ldc.i4.2 <null> br.s IL_008F: stloc.s V_10 ldloc.s V_4 callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.3 <null> ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_8 ldloc.s V_8 brfalse.s IL_00B4: ldc.i4.1 ldc.i4.6 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 ldc.i4.1 <null> br.s IL_00AD: stloc.s V_10 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> ldc.i4.1 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 nop <null> newobj System.Void System.Windows.Forms.PrintPreviewDialog::.ctor() stloc.s V_5 ldloc.s V_5 ldnull <null> callvirt System.Void System.Windows.Forms.PrintPreviewDialog::set_Document(System.Drawing.Printing.PrintDocument) nop <null> ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.3 <null> stloc.s V_10 br IL_0006: ldloc.s V_10 nop <null> ldc.i4.6 <null> ldc.i4.s 11 ldnull <null> ldc.i4 460434636 call System.String Jpt5e4j.Ha9sdq/Fca2f0Krcq.Rex3je8WP::rW_0Ke7xo5GkaC(System.Int32,System.Int32,Jpt5e4j.Ha9sdq/Fca2f0Krcq.Rex3je8WP,System.Int32) call System.Void 5esCa1.1Knsof::Got0g(System.String) nop <null> leave.s IL_0117: br.s IL_0119 br.s IL_0101: br.s IL_0103 br.s IL_0103: call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0117: br.s IL_0119 br.s IL_0119: ldc.i4.4 ldc.i4.4 <null> stloc.s V_12 ldloc.s V_12 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0139: nop nop <null> ret <null> ldtoken System.Void 5esCa1.1Knsof/fFr5Az4ww.Ert5oo0QcK::xx4JG0zsaNk37() pop <null> ret <null>

3242964b93864dc993de384b67e000d7 (747.01 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙