Suspicious
Suspect

4eba2e142789da90910a31f58753746d

PE Executable
|
MD5: 4eba2e142789da90910a31f58753746d
|
Size: 4.1 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
4eba2e142789da90910a31f58753746d
Sha1
7bac66043744abe189d8beb64f1e5f7030312594
Sha256
29edd1249136cb194f3947b5129c79d1725d2c4b670eb49bee8755ea37e6c813
Sha384
a043e68e08e54c2f6b73d8b4102e11cfd7bfbf2716b2da042c3ded45182e4192015be07f8959bc785d46fec70c46c936
Sha512
585b19c84839ab39f2480166fe2badc5abb6345a5e28abc66a77271222ce21d8e2c5d99ea219edd13e78b85d5c0b6f0fc0658a7c07fd6b07c00444201111031e
SSDeep
48:64Yol4wHFlqKAJ78KPIk+DRFoOul5hSbqnvpfbNtm:J4wHnREbwCBzNt
TLSH
A4816242A7EC8A2AF17747396EB347112776FD135EB6536D2698021A7E21A100CA3FB1

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

browser_launcher.exe

Full Name

browser_launcher.exe

EntryPoint

System.Void Program::Main()

Scope Name

browser_launcher.exe

Scope Type

ModuleDef

Kind

Console

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

browser_launcher

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

6

Main Method

System.Void Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> nop <null> ldstr chrome.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_001A: nop pop <null> nop <null> nop <null> leave.s IL_001A: nop nop <null> nop <null> ldstr msedge.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_0034: nop pop <null> nop <null> nop <null> leave.s IL_0034: nop nop <null> nop <null> ldstr firefox.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_004E: ret pop <null> nop <null> nop <null> leave.s IL_004E: ret ret <null>

Module Name

browser_launcher.exe

Full Name

browser_launcher.exe

EntryPoint

System.Void Program::Main()

Scope Name

browser_launcher.exe

Scope Type

ModuleDef

Kind

Console

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

browser_launcher

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

6

Main Method

System.Void Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> nop <null> ldstr chrome.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_001A: nop pop <null> nop <null> nop <null> leave.s IL_001A: nop nop <null> nop <null> ldstr msedge.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_0034: nop pop <null> nop <null> nop <null> leave.s IL_0034: nop nop <null> nop <null> ldstr firefox.exe ldstr https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String,System.String) pop <null> nop <null> leave.s IL_004E: ret pop <null> nop <null> nop <null> leave.s IL_004E: ret ret <null>

4eba2e142789da90910a31f58753746d (4.1 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙