Suspicious
Suspect

52311004d38f384a6ac3ab343709606f

PE Executable
|
MD5: 52311004d38f384a6ac3ab343709606f
|
Size: 956.93 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
52311004d38f384a6ac3ab343709606f
Sha1
62eb58de8c3abf7b3cc690c1bc27298a63e5d4ec
Sha256
ac63d72fec1ec402b35a0e03f9fc9ea635efba5114a66ebbb7177cbb7f9db507
Sha384
a10f3c728e10b020119b8bda83b16762d8199be75e48e8fdc1953695fe0bc5767e4ef254490ca4d2f57225fdda2cc54a
Sha512
cf1001ee2140c701eec26dab22f92510bff7ea4e5842aa36e753996eb6030e317812450cb1dfdcc263aadcb7fe7455d9e0abcaa174a1e6c69a17946d96befb01
SSDeep
24576:m7ERXeCtKkFeAvoC5EH5XyteU8vPDT5mGFSFvYb+:m7ERXeCtxFeAL5C5XfUcPH5ZK
TLSH
421512147A55EB32D4F987FA0771E63503B85E99A831D30A9EDA7CEF3922F042864743

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Medical_Store.Bill.resources
Medical_Store.Properties.Resources.resources
chb
wZdl
Informations
Name
Value
Module Name

HGDe.exe

Full Name

HGDe.exe

EntryPoint

System.Void Medical_Store.Program::Main()

Scope Name

HGDe.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

HGDe

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

354

Main Method

System.Void Medical_Store.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Medical_Store.Login::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

HGDe.exe

Full Name

HGDe.exe

EntryPoint

System.Void Medical_Store.Program::Main()

Scope Name

HGDe.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

HGDe

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

354

Main Method

System.Void Medical_Store.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Medical_Store.Login::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

13

Suspicious Type Names (1-2 chars)

0

52311004d38f384a6ac3ab343709606f (956.93 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙