Suspicious
Suspect

3a59dba58469d06be78f7831eabab72e

PE Executable
MD5: 3a59dba58469d06be78f7831eabab72e
Size: 1.52 MB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
3a59dba58469d06be78f7831eabab72e
Sha1
24670a4ae2fd1a1f62a8da1b5f870370a3926f8c
Sha256
ebaf8f3cf910b2a0e32e97c13712d6dc9ba62fc57ec456a55136420585755bbf
Sha384
cb80da6dde903ce4b86beb2a3283cf42e2f0eb3881d73930aba7ae853c8ede7a05cdb09b5e8b0e6c1672e388545e58ef
Sha512
debeee85f276408d32f7a875d371eb56f5166e3329ff009c0e2eab13f01c3d8b4d49a19e8bce3648f6f98699a3aef08da560b63b1bf5256462fb540c7c8f2e4a
SSDeep
24576:OfVdZhwZt804TaLOMvyKJa6wurTY6ezhlzYiZjT8WlBjXRM2682/8d64+a3BzkSd:OfVdXwJtBaKJvVrTY6El5OWlBzRMZ8/f
TLSH
776523656617C813E5911FB44C32D3F96B684E68E922D207DBEB3FAFB03A374145A1C2

PeID

ASProtect v1.32
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AvalancheRunner.OyinFormasi.resources
AvalancheRunner.Properties.Resources.resources
CKT
[NBF]root.Data
Gnsn
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

OCKR.exe

Full Name

OCKR.exe

EntryPoint

System.Void AvalancheRunner.Program::Main()

Scope Name

OCKR.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OCKR

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

94

Main Method

System.Void AvalancheRunner.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void AvalancheRunner.OyinFormasi::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

3a59dba58469d06be78f7831eabab72e (1.52 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙