Suspicious
Suspect

5600219fd9f02567a982da723ee2fc09

PE Executable
|
MD5: 5600219fd9f02567a982da723ee2fc09
|
Size: 799.23 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
5600219fd9f02567a982da723ee2fc09
Sha1
e980f9778e79c409742a05d6e3ece9297dcd629a
Sha256
fcc5f6575eaad95b3652072ce2947fb30e8afd5f70a5193ec5c828362adbd66b
Sha384
7206b6efe3e650f3a196cb9474118cb5d1d8148b5feee0ff08b2a672f6bbf0c16de061ae1855973ab555b104e3ad6031
Sha512
8334cc583a351932cafe4872334e9eb883ad050a897bf4f31684237293297d431ab996b439d7501e63eb17f57938b782ad12578d8e4410bac72222dfe99f851d
SSDeep
12288:7P3utjcG+XmttmEnb/off39s9L6njYf3ZX9NIsUawJ3YmOASuS/:zut5+ETEfuG63CywJ3Y7ASB
TLSH
ED050118225ADA03D1A28FF59972E3F417646F9AE821E7439FC63ECFB132B505581347

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
TravBot.Form1.resources
$this.Icon
[NBF]root.IconData
Timer_Cycle.TrayLocation
Timer_List.TrayLocation
squid
[NBF]root.Data
TravBot.UnmanagedCode.resources
TravBot.Properties.Resources.resources
wYCJ
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\gbvRsuLRRx\src\obj\Debug\hKzu.pdb

Module Name

hKzu.exe

Full Name

hKzu.exe

EntryPoint

System.Void TravBot.Program::Main()

Scope Name

hKzu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hKzu

Assembly Version

3.3.3.5

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

309

Main Method

System.Void TravBot.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void TravBot.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

hKzu.exe

Full Name

hKzu.exe

EntryPoint

System.Void TravBot.Program::Main()

Scope Name

hKzu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hKzu

Assembly Version

3.3.3.5

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

309

Main Method

System.Void TravBot.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void TravBot.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

5600219fd9f02567a982da723ee2fc09 (799.23 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙