Suspicious
Suspect

47754b51b133fe8df17a307c283f48d6

PE Executable
|
MD5: 47754b51b133fe8df17a307c283f48d6
|
Size: 573.44 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
47754b51b133fe8df17a307c283f48d6
Sha1
bab74ef74ac713930b2a8712a34babb06619b417
Sha256
8de658d191147b9e37ef7850ddffd5b36726c81002fe8144d8c89d5e79c9f790
Sha384
d7043b47d7401d0df0a124a622a9d67c9eeeadad2e525b9ecdf1565f4a4d1d46e3ac550013997c3d47784f6ec24af8cf
Sha512
9f89312c306b08440f725d986f53e2e93fbe13ce30bb84db43799ff85d7e9946a77850b5b1b5ec2240d09435bf756afb9cec94e2e382dd2cccc292711ef431f3
SSDeep
12288:x0OTMfwZIg/4vGVGN7DtKol41XQi+a37MaB+4TGDL9:+f+/4OYDIol8z37G4CDZ
TLSH
99C40148121AEB06D6A26BF81A72F274077C6E9DF412D21B8FD57EDF78B6B044D04293

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
zWvx
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: EaUO.pdb

Module Name

EaUO.exe

Full Name

EaUO.exe

EntryPoint

System.Void DiceSimulator.Program::Main()

Scope Name

EaUO.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

EaUO

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

235

Main Method

System.Void DiceSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DiceSimulator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

EaUO.exe

Full Name

EaUO.exe

EntryPoint

System.Void DiceSimulator.Program::Main()

Scope Name

EaUO.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

EaUO

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

235

Main Method

System.Void DiceSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DiceSimulator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

47754b51b133fe8df17a307c283f48d6 (573.44 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙