Suspicious
Suspect

43c1f601076e43b78ed1202ddfb745bb

PE Executable
|
MD5: 43c1f601076e43b78ed1202ddfb745bb
|
Size: 718.85 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
43c1f601076e43b78ed1202ddfb745bb
Sha1
5ee0a8e87be2c19b06de3d65be078eb54c46f9e9
Sha256
5d260ab0a4bc8f99007f1cf76420599dcee8e77fc0e6e201630f7b2ec824f085
Sha384
0a4e612b834779afd04844ff71792c733bdb16626cec6ebf2d0833f2ffb5ac424bcf31f6cc9106508a8a215706dd7bcc
Sha512
e7fd935981ead4fb67ca992464606d0831d130663aea5558043b5e998d638e0b95d15f8ca0fd9d13671e6015e1cbbf2a0261eba0de78d979729cced36f1cb05b
SSDeep
12288:gkBjuTwZD0xZ3Cp8DdsaDXgIr/4Hj3zS9pi/RH6M7wLe7GogUnBoxbdBEMUHWmfP:WIDWI6Dqv+/iUw/R67snBoxbHBUHWmFR
TLSH
12E41244B926DC13C5BA0BF14D51C2B853BD8DCDA522E3C3AECA2EEB74A67950D80707

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Module Name

usnk.exe

Full Name

usnk.exe

EntryPoint

System.Void SectorRepair.Program::Main()

Scope Name

usnk.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

usnk

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

320

Main Method

System.Void SectorRepair.Program::Main()

Main IL Instruction Count

7

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void SectorRepair.Program::InitializeApplication() newobj System.Void SectorRepair.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

usnk.exe

Full Name

usnk.exe

EntryPoint

System.Void SectorRepair.Program::Main()

Scope Name

usnk.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

usnk

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

320

Main Method

System.Void SectorRepair.Program::Main()

Main IL Instruction Count

7

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void SectorRepair.Program::InitializeApplication() newobj System.Void SectorRepair.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Artefacts
Name
Value
Embedded Resources

5

Suspicious Type Names (1-2 chars)

0

43c1f601076e43b78ed1202ddfb745bb (718.85 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙