Suspicious
Suspect

5452f380783a7377e36e8f55e15ae820

PE Executable
|
MD5: 5452f380783a7377e36e8f55e15ae820
|
Size: 792.06 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
5452f380783a7377e36e8f55e15ae820
Sha1
2cc4f8a93426b8191e6c28b83122a1ab31b79643
Sha256
307d7ca2638da45222b734f2b6c41f923d19e43bc3e9f81e2365930e856fd2e2
Sha384
e656e908e6745042a72aba16525600276eecaf86f05ae84ef43e1bd80913ec0a9a0bf719cf2ee4589252f7daefff6011
Sha512
82c4f3718d235f3806a14a5f1395ea098bb45e5dd5f0b652235b483de1839a6e85b7971dca1a68b96dac3ef174abb7693e4b6dfb09755cb37980b9aa03081b38
SSDeep
12288:gkCcFFTFWxd9uMT4E4E0DlxpM/7SNym3xrevklPo5rBw7r5z/Z/hkVEI3iAkYI9t:guFxWPUk4EILOK3ukZ7r5z/5hk
TLSH
28F4C0AD3355B99FC467CA7189A4EE7496207CAA9707C20381D71D9FB91CA83CE142F3

PeID

.NET executable
HQR data file
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
Teacher
[NBF]root.Data
caaA
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

xsED.exe

Full Name

xsED.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

xsED.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xsED

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> ldc.i4 1741027421 ldc.i4 2012011722 xor <null> dup <null> stloc.0 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_006F: nop newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‮​‏‪‫‮‍‮‍‍‭‮​‏‮‭‬​‬‬​‎‪‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1214691332 mul <null> ldc.i4 1437836944 xor <null> br.s IL_0006: ldc.i4 2012011722 nop <null> ldloc.0 <null> ldc.i4 -1356809116 mul <null> ldc.i4 1518755417 xor <null> br.s IL_0006: ldc.i4 2012011722 call System.Void ClipboardAnalyzer.Program::‏‫‮‬‮‍‫‮‫‎‏‮‎‌‫​‍‬‫‮() nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‫‏‬‬‭‌‍‫‍‏‮‫‌​‭‫‏‮‬​‮‎‫​‮(System.Boolean) ldloc.0 <null> ldc.i4 -881200439 mul <null> ldc.i4 -2058259260 xor <null> br.s IL_0006: ldc.i4 2012011722 nop <null> ret <null>

Module Name

xsED.exe

Full Name

xsED.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

xsED.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xsED

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> ldc.i4 1741027421 ldc.i4 2012011722 xor <null> dup <null> stloc.0 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_006F: nop newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‮​‏‪‫‮‍‮‍‍‭‮​‏‮‭‬​‬‬​‎‪‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1214691332 mul <null> ldc.i4 1437836944 xor <null> br.s IL_0006: ldc.i4 2012011722 nop <null> ldloc.0 <null> ldc.i4 -1356809116 mul <null> ldc.i4 1518755417 xor <null> br.s IL_0006: ldc.i4 2012011722 call System.Void ClipboardAnalyzer.Program::‏‫‮‬‮‍‫‮‫‎‏‮‎‌‫​‍‬‫‮() nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‫‏‬‬‭‌‍‫‍‏‮‫‌​‭‫‏‮‬​‮‎‫​‮(System.Boolean) ldloc.0 <null> ldc.i4 -881200439 mul <null> ldc.i4 -2058259260 xor <null> br.s IL_0006: ldc.i4 2012011722 nop <null> ret <null>

5452f380783a7377e36e8f55e15ae820 (792.06 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙