Suspicious
Suspect

3434e481c5c7e26dd7485ab9482f9fa4

PE Executable
|
MD5: 3434e481c5c7e26dd7485ab9482f9fa4
|
Size: 794.11 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
3434e481c5c7e26dd7485ab9482f9fa4
Sha1
0096fe124a712dfb9f34306fec8bafb9fb9eda46
Sha256
1aace65d005ccd6fb6d04dc4ae6d59956f9457667e179316f6f580f24096d691
Sha384
66389940367a547a10a7c64c088edf0424345446e0e2850b1fcc89bf35554f25416b9dc89306f8eb1574ebcebd6c2dab
Sha512
9583a2f1bca85c2d92b0accf13b0e1a40c439592c1c031bcebacd0a4949f525ec7e1cf24ce65226cefd6085bbbc3fb132f3f0b2ea066e8037b7640eae469c328
SSDeep
12288:Ggr/Qnbx3Gomp3ux6JomvfYFREhQEBW0WzCNVUvbwFZIrsO9n:vQnbx3Gz3Seoos6Q3WNmbwF0sO9n
TLSH
19F40168229A9F03C0BF07FA1512D0F4537ABECEA151E3198FC22CEB7D657960506B5B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Module Name

oYtu.exe

Full Name

oYtu.exe

EntryPoint

System.Void RepositoryModule.Program::Main()

Scope Name

oYtu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

oYtu

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

679

Main Method

System.Void RepositoryModule.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void RepositoryModule.Program::InitializeApplication() nop <null> newobj System.Void RepositoryModule.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

oYtu.exe

Full Name

oYtu.exe

EntryPoint

System.Void RepositoryModule.Program::Main()

Scope Name

oYtu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

oYtu

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

679

Main Method

System.Void RepositoryModule.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void RepositoryModule.Program::InitializeApplication() nop <null> newobj System.Void RepositoryModule.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

8

Suspicious Type Names (1-2 chars)

0

3434e481c5c7e26dd7485ab9482f9fa4 (794.11 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙