Suspicious
Suspect

4f044faa93923a93ce87dfd862258871

PE Executable
|
MD5: 4f044faa93923a93ce87dfd862258871
|
Size: 998.4 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
4f044faa93923a93ce87dfd862258871
Sha1
3b6b07a2c2bb7d3b5b355a02e353535a8d5466e9
Sha256
84f2e7778e3a25f2b9900ddfdfce6bbc39a6814f791c44100fd7d35d38dd95af
Sha384
ac184fc5c9ff44be6ec21851024e26543cd57c66a7da2775edc3e88e16b9d3f1d9d1cfd76c9d538895798a7ecb64edd5
Sha512
5b5d03559aaa7d0232e6422420a873ab18e19e28ad4dd797381f4f3a715ff7e1a942b4a7dc474c796d8ae5ebb758abb66509e60e0de71c2ba5c905b4c0426a6b
SSDeep
24576:l9CBkTM6m0WyzBYH5NFSMR1xGxZLMTyTK8884:l9CBkbm0W5HH0yeZYYd88
TLSH
2E251218A6ADDFA3D1FD07F81570D3B623B65C9DA401D3068EDEECE378527402A906A7

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
VirtualWrapper.MainForm.resources
VirtualWrapper.Properties.Resources.resources
Pdkuw
k0
Informations
Name
Value
Module Name

ewGOC.exe

Full Name

ewGOC.exe

EntryPoint

System.Void VirtualWrapper.Program::Main()

Scope Name

ewGOC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ewGOC

Assembly Version

5.6.14.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

650

Main Method

System.Void VirtualWrapper.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void VirtualWrapper.Program::InitializeApplication() nop <null> newobj System.Void VirtualWrapper.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

ewGOC.exe

Full Name

ewGOC.exe

EntryPoint

System.Void VirtualWrapper.Program::Main()

Scope Name

ewGOC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ewGOC

Assembly Version

5.6.14.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

650

Main Method

System.Void VirtualWrapper.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void VirtualWrapper.Program::InitializeApplication() nop <null> newobj System.Void VirtualWrapper.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

9

Suspicious Type Names (1-2 chars)

0

4f044faa93923a93ce87dfd862258871 (998.4 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙