Suspicious
Suspect

4a6b939beb42f3588ee9cb86bb646158

PE Executable
|
MD5: 4a6b939beb42f3588ee9cb86bb646158
|
Size: 719.87 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
4a6b939beb42f3588ee9cb86bb646158
Sha1
f10dd3a1c30f48393c68fac944c489616dcd8006
Sha256
326bcb8456524b7a385028d507b09df71fb56dde16100fa3f753a10d59f4c752
Sha384
89d86a93970d6ba394bb4b59fa960c8adc36a951bf5f6712b6d5258fafe90ff5d4a5c6b5a95e8557f408e32a8194313a
Sha512
c8e608789e5d825dec36f70a671fb9fd45964543f9b2b51c780994c16c61795dd6f7e1ea34a52bb2a761fc89191a62eb249e4e69396ab08edc51ffbce6ad623b
SSDeep
12288:sjGYeKqOZQ8h44udD6p7bx5WzMVMFOzrBG9Nzd2TwjQ6zGTT67UWOAO+cviqL:sjFNRQ84LdedbKzk7rBwNzUTwM
TLSH
7AE4AEAC3210B89EC453CE728E74DD70AA247D7A9707C20395D71DAFB91DA96DE002F2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
hbRs
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

DLcD.exe

Full Name

DLcD.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

DLcD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

DLcD

Assembly Version

3.7.2.4

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

75

Main IL

nop <null> ldc.i4 -133843745 ldc.i4 -1032639177 xor <null> dup <null> stloc.1 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0064: nop call System.Void EventLogAnalyzer.Program::‫‭‍‍‮‬​‬‫‪​‪‍‏‪‬‬‬​‮‭‬‍‮‌‌‫‮() ldloc.1 <null> ldc.i4 -1783019940 mul <null> ldc.i4 359670237 xor <null> br.s IL_0006: ldc.i4 -1032639177 nop <null> ldloc.1 <null> ldc.i4 499836774 mul <null> ldc.i4 -316781668 xor <null> br.s IL_0006: ldc.i4 -1032639177 ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‬‫‍‏‫‍‌‮‪‎‪‫‮‪‭‍‍​‍‫‍​‪‮‎‮(System.Boolean) ldloc.1 <null> ldc.i4 1602090038 mul <null> ldc.i4 -690382356 xor <null> br.s IL_0006: ldc.i4 -1032639177 nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‬‌‎‏‪‭‌‭‮‭​‌‬‌‌‮‪‪‏‭‍‪‬‍‪‬‏‮‮(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_00E0: ret stloc.0 <null> ldc.i4 -997515194 ldc.i4 -1032639177 xor <null> dup <null> stloc.1 <null> ldc.i4.4 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00DD: nop nop <null> ldloc.1 <null> ldc.i4 1673514075 mul <null> ldc.i4 1848329362 xor <null> br.s IL_007A: ldc.i4 -1032639177 ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‫​‬‪‪‫‮‭‪​​‪‏‍‎​‮‎‍‮‪‮‭‍‫‪‮‬​‏‏‎‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‮​‌‭‌‏‏‮‍‍‏​‎‫‪‍‏​‫‮‬‍‏‮‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‌‎‌‬‏‮‮‌​​‮‪‍‎‮‮‪‬‪‬‫‬‏‪‌‏‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldloc.1 <null> ldc.i4 -559274812 mul <null> ldc.i4 -969735568 xor <null> br.s IL_007A: ldc.i4 -1032639177 nop <null> leave.s IL_00E0: ret ret <null>

Module Name

DLcD.exe

Full Name

DLcD.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

DLcD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

DLcD

Assembly Version

3.7.2.4

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

75

Main IL

nop <null> ldc.i4 -133843745 ldc.i4 -1032639177 xor <null> dup <null> stloc.1 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0064: nop call System.Void EventLogAnalyzer.Program::‫‭‍‍‮‬​‬‫‪​‪‍‏‪‬‬‬​‮‭‬‍‮‌‌‫‮() ldloc.1 <null> ldc.i4 -1783019940 mul <null> ldc.i4 359670237 xor <null> br.s IL_0006: ldc.i4 -1032639177 nop <null> ldloc.1 <null> ldc.i4 499836774 mul <null> ldc.i4 -316781668 xor <null> br.s IL_0006: ldc.i4 -1032639177 ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‬‫‍‏‫‍‌‮‪‎‪‫‮‪‭‍‍​‍‫‍​‪‮‎‮(System.Boolean) ldloc.1 <null> ldc.i4 1602090038 mul <null> ldc.i4 -690382356 xor <null> br.s IL_0006: ldc.i4 -1032639177 nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‬‌‎‏‪‭‌‭‮‭​‌‬‌‌‮‪‪‏‭‍‪‬‍‪‬‏‮‮(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_00E0: ret stloc.0 <null> ldc.i4 -997515194 ldc.i4 -1032639177 xor <null> dup <null> stloc.1 <null> ldc.i4.4 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00DD: nop nop <null> ldloc.1 <null> ldc.i4 1673514075 mul <null> ldc.i4 1848329362 xor <null> br.s IL_007A: ldc.i4 -1032639177 ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‫​‬‪‪‫‮‭‪​​‪‏‍‎​‮‎‍‮‪‮‭‍‫‪‮‬​‏‏‎‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‮​‌‭‌‏‏‮‍‍‏​‎‫‪‍‏​‫‮‬‍‏‮‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‌‎‌‬‏‮‮‌​​‮‪‍‎‮‮‪‬‪‬‫‬‏‪‌‏‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldloc.1 <null> ldc.i4 -559274812 mul <null> ldc.i4 -969735568 xor <null> br.s IL_007A: ldc.i4 -1032639177 nop <null> leave.s IL_00E0: ret ret <null>

4a6b939beb42f3588ee9cb86bb646158 (719.87 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
hbRs
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙