Suspicious
Suspect

52e4b2a78d75d465aca0e7b4ffd25e72

PE Executable
|
MD5: 52e4b2a78d75d465aca0e7b4ffd25e72
|
Size: 2.02 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
52e4b2a78d75d465aca0e7b4ffd25e72
Sha1
aac30262eb8243dafe9c87be9643244df230ddfe
Sha256
73ea1a25e53982c23589384c60d95fe3918830d739e8ed2d9e0496dd9c8d599a
Sha384
b5fb9609704b0634a155ca6db05029e5c261e6fb88cd274cea3630101248ce10f35279681c3e209955cc9b4b0e80f032
Sha512
0ce086bed75db5df3063e6bdf028458a6c59983df6afb5ea28a6487ead92413137da24c94cc6aa1af1f3c94d4b19896cb29d38bfbff9fa2e430b9ced39ecc3be
SSDeep
24576:dLUSTi3AuSmCsQcAPNKh2V0/eS9BrVXqI+mRzW/BV:JUSupSmpQFNKkW/pVaIDZW
TLSH
7595E01227D82F58F07FAB385478560447FABC02DF22DF9DBDEC59992931B418662B23

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
6KycfbX8pW.g.resources
6KycfbX8pW.Q_m8jC1pB9dd.resources
d1d5b617d5a187.Resources.resources
88aab7d90
[NBF]root.Data
88aab7d91
[NBF]root.Data
88aab7d910
[NBF]root.Data
88aab7d911
[NBF]root.Data
88aab7d912
[NBF]root.Data
88aab7d913
[NBF]root.Data
88aab7d914
[NBF]root.Data
88aab7d915
[NBF]root.Data
88aab7d916
[NBF]root.Data
88aab7d917
[NBF]root.Data
88aab7d918
[NBF]root.Data
88aab7d919
[NBF]root.Data
88aab7d92
[NBF]root.Data
88aab7d920
[NBF]root.Data
88aab7d921
[NBF]root.Data
88aab7d922
[NBF]root.Data
88aab7d923
[NBF]root.Data
88aab7d924
[NBF]root.Data
88aab7d925
[NBF]root.Data
88aab7d926
[NBF]root.Data
88aab7d927
[NBF]root.Data
88aab7d928
[NBF]root.Data
88aab7d929
[NBF]root.Data
88aab7d93
[NBF]root.Data
88aab7d930
[NBF]root.Data
88aab7d931
[NBF]root.Data
88aab7d932
[NBF]root.Data
88aab7d933
[NBF]root.Data
88aab7d934
[NBF]root.Data
88aab7d935
[NBF]root.Data
88aab7d936
[NBF]root.Data
88aab7d937
[NBF]root.Data
88aab7d938
[NBF]root.Data
88aab7d939
[NBF]root.Data
88aab7d94
[NBF]root.Data
88aab7d940
[NBF]root.Data
88aab7d941
[NBF]root.Data
88aab7d942
[NBF]root.Data
88aab7d943
[NBF]root.Data
88aab7d944
[NBF]root.Data
88aab7d945
[NBF]root.Data
88aab7d946
[NBF]root.Data
88aab7d947
[NBF]root.Data
88aab7d948
[NBF]root.Data
88aab7d949
[NBF]root.Data
88aab7d95
[NBF]root.Data
88aab7d950
[NBF]root.Data
88aab7d951
[NBF]root.Data
88aab7d952
[NBF]root.Data
88aab7d953
[NBF]root.Data
88aab7d954
[NBF]root.Data
88aab7d955
[NBF]root.Data
88aab7d956
[NBF]root.Data
88aab7d957
[NBF]root.Data
88aab7d958
[NBF]root.Data
88aab7d959
[NBF]root.Data
88aab7d96
[NBF]root.Data
88aab7d960
[NBF]root.Data
88aab7d961
[NBF]root.Data
88aab7d962
[NBF]root.Data
88aab7d963
[NBF]root.Data
88aab7d964
[NBF]root.Data
88aab7d965
[NBF]root.Data
88aab7d97
[NBF]root.Data
88aab7d98
[NBF]root.Data
88aab7d99
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

6KycfbX8pW

Full Name

6KycfbX8pW

EntryPoint

System.Void 6KycfbX8pW.Q_m8jC1pB9dd::wTg67()

Scope Name

6KycfbX8pW

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6KycfbX8pW

Assembly Version

17.29.44.84

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1896

Main Method

System.Void 6KycfbX8pW.Q_m8jC1pB9dd::wTg67()

Main IL Instruction Count

166

Main IL

nop <null> nop <null> call System.Threading.Thread System.Threading.Thread::get_CurrentThread() callvirt System.Threading.ApartmentState System.Threading.Thread::GetApartmentState() ldc.i4.1 <null> ceq <null> stloc.s V_18 ldloc.s V_18 brfalse.s IL_0022: nop call System.Threading.Thread System.Threading.Thread::get_CurrentThread() ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState) nop <null> nop <null> nop <null> call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture() stloc.0 <null> ldloc.0 <null> call System.Void System.Globalization.CultureInfo::set_CurrentCulture(System.Globalization.CultureInfo) nop <null> ldloc.0 <null> call System.Void System.Globalization.CultureInfo::set_CurrentUICulture(System.Globalization.CultureInfo) nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() stloc.1 <null> ldstr 1.0.0.0 stloc.2 <null> nop <null> ldloc.1 <null> callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) stloc.s V_19 ldloc.s V_19 callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.2 <null> leave.s IL_0068: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0068: nop nop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) stloc.3 <null> ldloc.3 <null> ldstr SystemServices ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_4 ldloc.s V_4 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_20 ldloc.s V_20 brfalse.s IL_009C: nop ldloc.s V_4 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldc.i4.1 <null> stloc.s V_5 ldc.r8 25 call System.Double System.Math::Floor(System.Double) conv.ovf.i4 <null> stloc.s V_6 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.s V_7 call System.String 6KycfbX8pW.Q_m8jC1pB9dd/cSy5b4Lg.aYk6q4MpF::fx2NTdn7() call System.Byte[] 6KycfbX8pW.2TmxCbn8::kt9Rb(System.String) stloc.s V_8 call System.Boolean System.Environment::get_UserInteractive() stloc.s V_9 ldc.i4 32807 stloc.s V_10 call System.Drawing.Rectangle System.Windows.Forms.SystemInformation::get_VirtualScreen() stloc.s V_21 ldloca.s V_21 call System.Int32 System.Drawing.Rectangle::get_Width() stloc.s V_11 ldloc.s V_8 castclass System.Byte[] ldloc.s V_10 call System.Object 6KycfbX8pW.3Sfoe1pG::9Data1LfZp(System.Byte[],System.Int32) ldnull <null> ldstr ToArray ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) castclass System.Byte[] stloc.s V_12 ldloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldloc.s V_12 stelem.ref <null> ldc.i4.0 <null> call System.Int64 System.GC::GetTotalMemory(System.Boolean) ldc.i4 104857600 conv.i8 <null> cgt <null> stloc.s V_13 call System.Drawing.Rectangle System.Windows.Forms.Cursor::get_Clip() stloc.s V_21 ldloca.s V_21 call System.Boolean System.Drawing.Rectangle::get_IsEmpty() stloc.s V_14 ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_15 ldloc.s V_15 ldstr Load ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldtoken System.Byte[] call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stelem.ref <null> callvirt System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Type[]) stloc.s V_16 ldloc.s V_16 ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldelem.ref <null> stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_17 ldloc.s V_7 ldloc.s V_6 ldc.i4.6 <null> sub.ovf <null> ldloc.s V_17 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.s V_7 ldloc.s V_6 call System.Void 6KycfbX8pW.Q_m8jC1pB9dd/1Gjoir.oj3LBp::7ZbwwxC3i(System.Object[],System.Int32) nop <null> leave.s IL_01B0: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_22 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_01B0: nop nop <null> ret <null>

Module Name

6KycfbX8pW

Full Name

6KycfbX8pW

EntryPoint

System.Void 6KycfbX8pW.Q_m8jC1pB9dd::wTg67()

Scope Name

6KycfbX8pW

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6KycfbX8pW

Assembly Version

17.29.44.84

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1896

Main Method

System.Void 6KycfbX8pW.Q_m8jC1pB9dd::wTg67()

Main IL Instruction Count

166

Main IL

nop <null> nop <null> call System.Threading.Thread System.Threading.Thread::get_CurrentThread() callvirt System.Threading.ApartmentState System.Threading.Thread::GetApartmentState() ldc.i4.1 <null> ceq <null> stloc.s V_18 ldloc.s V_18 brfalse.s IL_0022: nop call System.Threading.Thread System.Threading.Thread::get_CurrentThread() ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState) nop <null> nop <null> nop <null> call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture() stloc.0 <null> ldloc.0 <null> call System.Void System.Globalization.CultureInfo::set_CurrentCulture(System.Globalization.CultureInfo) nop <null> ldloc.0 <null> call System.Void System.Globalization.CultureInfo::set_CurrentUICulture(System.Globalization.CultureInfo) nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() stloc.1 <null> ldstr 1.0.0.0 stloc.2 <null> nop <null> ldloc.1 <null> callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) stloc.s V_19 ldloc.s V_19 callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.2 <null> leave.s IL_0068: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0068: nop nop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) stloc.3 <null> ldloc.3 <null> ldstr SystemServices ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_4 ldloc.s V_4 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_20 ldloc.s V_20 brfalse.s IL_009C: nop ldloc.s V_4 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldc.i4.1 <null> stloc.s V_5 ldc.r8 25 call System.Double System.Math::Floor(System.Double) conv.ovf.i4 <null> stloc.s V_6 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.s V_7 call System.String 6KycfbX8pW.Q_m8jC1pB9dd/cSy5b4Lg.aYk6q4MpF::fx2NTdn7() call System.Byte[] 6KycfbX8pW.2TmxCbn8::kt9Rb(System.String) stloc.s V_8 call System.Boolean System.Environment::get_UserInteractive() stloc.s V_9 ldc.i4 32807 stloc.s V_10 call System.Drawing.Rectangle System.Windows.Forms.SystemInformation::get_VirtualScreen() stloc.s V_21 ldloca.s V_21 call System.Int32 System.Drawing.Rectangle::get_Width() stloc.s V_11 ldloc.s V_8 castclass System.Byte[] ldloc.s V_10 call System.Object 6KycfbX8pW.3Sfoe1pG::9Data1LfZp(System.Byte[],System.Int32) ldnull <null> ldstr ToArray ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) castclass System.Byte[] stloc.s V_12 ldloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldloc.s V_12 stelem.ref <null> ldc.i4.0 <null> call System.Int64 System.GC::GetTotalMemory(System.Boolean) ldc.i4 104857600 conv.i8 <null> cgt <null> stloc.s V_13 call System.Drawing.Rectangle System.Windows.Forms.Cursor::get_Clip() stloc.s V_21 ldloca.s V_21 call System.Boolean System.Drawing.Rectangle::get_IsEmpty() stloc.s V_14 ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_15 ldloc.s V_15 ldstr Load ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldtoken System.Byte[] call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stelem.ref <null> callvirt System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Type[]) stloc.s V_16 ldloc.s V_16 ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> sub.ovf <null> ldelem.ref <null> stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_17 ldloc.s V_7 ldloc.s V_6 ldc.i4.6 <null> sub.ovf <null> ldloc.s V_17 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.s V_7 ldloc.s V_6 call System.Void 6KycfbX8pW.Q_m8jC1pB9dd/1Gjoir.oj3LBp::7ZbwwxC3i(System.Object[],System.Int32) nop <null> leave.s IL_01B0: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_22 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_01B0: nop nop <null> ret <null>

52e4b2a78d75d465aca0e7b4ffd25e72 (2.02 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙