Suspicious
Suspect

56e257f481be84feb046cb2a82a89fca

PE Executable
|
MD5: 56e257f481be84feb046cb2a82a89fca
|
Size: 12.28 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
56e257f481be84feb046cb2a82a89fca
Sha1
cdceb4a49b9d09cffd19cac5241aab3ec5ded43c
Sha256
20fb502b4133cd354c56502fcf3813844020773bc806682efebd217b47d394cf
Sha384
ce9b185c78a57941cbce223bc64a4a2c57030da77726d7f19acee5b52db01e7439349d94102fd42a85777e1b2e454927
Sha512
1ca7c5d92876e9bfe1805bddce2eeeb5aba450dffeeed353122a32fb97aff976ad40510e7e373eaaba41017839a09a895d3e1ecd59a326136e928175f95e62ee
SSDeep
98304:l0trB03LpTThUMidHSCOX32FAhpWYZxlxA+13Y:p39h9iXcDUqlH13
TLSH
0CC6341B6AE301B5E4E9CE34A7B944FC46F16B2F5620B7BB154012F8CE6074A75236B3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Overlay_0965586d.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
.Net Resources
fXt46boBycQ5r.Resources.resources
07baada2104cac.Resources.resources
55a374bc0
[NBF]root.Data
55a374bc1
[NBF]root.Data
55a374bc10
[NBF]root.Data
55a374bc100
[NBF]root.Data
55a374bc101
[NBF]root.Data
55a374bc102
[NBF]root.Data
55a374bc103
[NBF]root.Data
55a374bc104
[NBF]root.Data
55a374bc105
[NBF]root.Data
55a374bc106
[NBF]root.Data
55a374bc107
[NBF]root.Data
55a374bc108
[NBF]root.Data
55a374bc109
[NBF]root.Data
55a374bc11
[NBF]root.Data
55a374bc110
[NBF]root.Data
55a374bc111
[NBF]root.Data
55a374bc112
[NBF]root.Data
55a374bc113
[NBF]root.Data
55a374bc114
[NBF]root.Data
55a374bc115
[NBF]root.Data
55a374bc116
[NBF]root.Data
55a374bc117
[NBF]root.Data
55a374bc118
[NBF]root.Data
55a374bc119
[NBF]root.Data
55a374bc12
[NBF]root.Data
55a374bc120
[NBF]root.Data
55a374bc121
[NBF]root.Data
55a374bc122
[NBF]root.Data
55a374bc123
[NBF]root.Data
55a374bc124
[NBF]root.Data
55a374bc125
[NBF]root.Data
55a374bc126
[NBF]root.Data
55a374bc127
[NBF]root.Data
55a374bc128
[NBF]root.Data
55a374bc129
[NBF]root.Data
55a374bc13
[NBF]root.Data
55a374bc130
[NBF]root.Data
55a374bc131
[NBF]root.Data
55a374bc132
[NBF]root.Data
55a374bc133
[NBF]root.Data
55a374bc14
[NBF]root.Data
55a374bc15
[NBF]root.Data
55a374bc16
[NBF]root.Data
55a374bc17
[NBF]root.Data
55a374bc18
[NBF]root.Data
55a374bc19
[NBF]root.Data
55a374bc2
[NBF]root.Data
55a374bc20
[NBF]root.Data
55a374bc21
[NBF]root.Data
55a374bc22
[NBF]root.Data
55a374bc23
[NBF]root.Data
55a374bc24
[NBF]root.Data
55a374bc25
[NBF]root.Data
55a374bc26
[NBF]root.Data
55a374bc27
[NBF]root.Data
55a374bc28
[NBF]root.Data
55a374bc29
[NBF]root.Data
55a374bc3
[NBF]root.Data
55a374bc30
[NBF]root.Data
55a374bc31
[NBF]root.Data
55a374bc32
[NBF]root.Data
55a374bc33
[NBF]root.Data
55a374bc34
[NBF]root.Data
55a374bc35
[NBF]root.Data
55a374bc36
[NBF]root.Data
55a374bc37
[NBF]root.Data
55a374bc38
[NBF]root.Data
55a374bc39
[NBF]root.Data
55a374bc4
[NBF]root.Data
55a374bc40
[NBF]root.Data
55a374bc41
[NBF]root.Data
55a374bc42
[NBF]root.Data
55a374bc43
[NBF]root.Data
55a374bc44
[NBF]root.Data
55a374bc45
[NBF]root.Data
55a374bc46
[NBF]root.Data
55a374bc47
[NBF]root.Data
55a374bc48
[NBF]root.Data
55a374bc49
[NBF]root.Data
55a374bc5
[NBF]root.Data
55a374bc50
[NBF]root.Data
55a374bc51
[NBF]root.Data
55a374bc52
[NBF]root.Data
55a374bc53
[NBF]root.Data
55a374bc54
[NBF]root.Data
55a374bc55
[NBF]root.Data
55a374bc56
[NBF]root.Data
55a374bc57
[NBF]root.Data
55a374bc58
[NBF]root.Data
55a374bc59
[NBF]root.Data
55a374bc6
[NBF]root.Data
55a374bc60
[NBF]root.Data
55a374bc61
[NBF]root.Data
55a374bc62
[NBF]root.Data
55a374bc63
[NBF]root.Data
55a374bc64
[NBF]root.Data
55a374bc65
[NBF]root.Data
55a374bc66
[NBF]root.Data
55a374bc67
[NBF]root.Data
55a374bc68
[NBF]root.Data
55a374bc69
[NBF]root.Data
55a374bc7
[NBF]root.Data
55a374bc70
[NBF]root.Data
55a374bc71
[NBF]root.Data
55a374bc72
[NBF]root.Data
55a374bc73
[NBF]root.Data
55a374bc74
[NBF]root.Data
55a374bc75
[NBF]root.Data
55a374bc76
[NBF]root.Data
55a374bc77
[NBF]root.Data
55a374bc78
[NBF]root.Data
55a374bc79
[NBF]root.Data
55a374bc8
[NBF]root.Data
55a374bc80
[NBF]root.Data
55a374bc81
[NBF]root.Data
55a374bc82
[NBF]root.Data
55a374bc83
[NBF]root.Data
55a374bc84
[NBF]root.Data
55a374bc85
[NBF]root.Data
55a374bc86
[NBF]root.Data
55a374bc87
[NBF]root.Data
55a374bc88
[NBF]root.Data
55a374bc89
[NBF]root.Data
55a374bc9
[NBF]root.Data
55a374bc90
[NBF]root.Data
55a374bc91
[NBF]root.Data
55a374bc92
[NBF]root.Data
55a374bc93
[NBF]root.Data
55a374bc94
[NBF]root.Data
55a374bc95
[NBF]root.Data
55a374bc96
[NBF]root.Data
55a374bc97
[NBF]root.Data
55a374bc98
[NBF]root.Data
55a374bc99
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_0965586d.bin (4975608 bytes)

Module Name

fXt46boBycQ5r

Full Name

fXt46boBycQ5r

EntryPoint

System.Void fXt46boBycQ5r.6Kbyw1x::kXa03()

Scope Name

fXt46boBycQ5r

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

fXt46boBycQ5r

Assembly Version

18.0.240.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1862

Main Method

System.Void fXt46boBycQ5r.6Kbyw1x::kXa03()

Main IL Instruction Count

86

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> nop <null> ldstr Initializing... stloc.1 <null> call System.OperatingSystem System.Environment::get_OSVersion() callvirt System.Version System.OperatingSystem::get_Version() callvirt System.Int32 System.Version::get_Major() ldc.i4.6 <null> clt <null> ldc.i4.0 <null> ceq <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_0037: nop call System.Boolean fXt46boBycQ5r.6Kbyw1x::Xeq51mLbaR() pop <null> nop <null> nop <null> newobj System.Void fXt46boBycQ5r.ap5BP::.ctor() call System.Object fXt46boBycQ5r.Ptt23gHxfQ::ag9Ha0Td7Jbk() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Collections.Generic.List`1<System.Byte> fXt46boBycQ5r.6Kbyw1x::9xnY_(System.Object) callvirt System.Byte[] System.Collections.Generic.List`1<System.Byte>::ToArray() ldc.i4.s 9 newarr System.String dup <null> ldc.i4.0 <null> ldstr 117 stelem.ref <null> dup <null> ldc.i4.1 <null> ldstr 114 stelem.ref <null> dup <null> ldc.i4.2 <null> ldstr 106 stelem.ref <null> dup <null> ldc.i4.3 <null> ldstr 110 stelem.ref <null> dup <null> ldc.i4.4 <null> ldstr 118 stelem.ref <null> dup <null> ldc.i4.5 <null> ldstr 117 stelem.ref <null> dup <null> ldc.i4.6 <null> ldstr 97 stelem.ref <null> dup <null> ldc.i4.7 <null> ldstr 98 stelem.ref <null> dup <null> ldc.i4.8 <null> ldstr 111 stelem.ref <null> ldsfld System.Int32 fXt46boBycQ5r.Ptt23gHxfQ/8CorfiE.2GszRfy69::1giSm4Rrtp8Dj2 call System.Object fXt46boBycQ5r.ap5BP::4mjJRc8w(System.Byte[],System.String[],System.Int32) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> ldc.r8 1.087 stloc.0 <null> ldloc.2 <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object fXt46boBycQ5r.Ptt23gHxfQ::5Pjfc4yMg(System.Object) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.3 <null> leave.s IL_00DD: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_5 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00DD: nop nop <null> ret <null>

Module Name

fXt46boBycQ5r

Full Name

fXt46boBycQ5r

EntryPoint

System.Void fXt46boBycQ5r.6Kbyw1x::kXa03()

Scope Name

fXt46boBycQ5r

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

fXt46boBycQ5r

Assembly Version

18.0.240.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1862

Main Method

System.Void fXt46boBycQ5r.6Kbyw1x::kXa03()

Main IL Instruction Count

86

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> nop <null> ldstr Initializing... stloc.1 <null> call System.OperatingSystem System.Environment::get_OSVersion() callvirt System.Version System.OperatingSystem::get_Version() callvirt System.Int32 System.Version::get_Major() ldc.i4.6 <null> clt <null> ldc.i4.0 <null> ceq <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_0037: nop call System.Boolean fXt46boBycQ5r.6Kbyw1x::Xeq51mLbaR() pop <null> nop <null> nop <null> newobj System.Void fXt46boBycQ5r.ap5BP::.ctor() call System.Object fXt46boBycQ5r.Ptt23gHxfQ::ag9Ha0Td7Jbk() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Collections.Generic.List`1<System.Byte> fXt46boBycQ5r.6Kbyw1x::9xnY_(System.Object) callvirt System.Byte[] System.Collections.Generic.List`1<System.Byte>::ToArray() ldc.i4.s 9 newarr System.String dup <null> ldc.i4.0 <null> ldstr 117 stelem.ref <null> dup <null> ldc.i4.1 <null> ldstr 114 stelem.ref <null> dup <null> ldc.i4.2 <null> ldstr 106 stelem.ref <null> dup <null> ldc.i4.3 <null> ldstr 110 stelem.ref <null> dup <null> ldc.i4.4 <null> ldstr 118 stelem.ref <null> dup <null> ldc.i4.5 <null> ldstr 117 stelem.ref <null> dup <null> ldc.i4.6 <null> ldstr 97 stelem.ref <null> dup <null> ldc.i4.7 <null> ldstr 98 stelem.ref <null> dup <null> ldc.i4.8 <null> ldstr 111 stelem.ref <null> ldsfld System.Int32 fXt46boBycQ5r.Ptt23gHxfQ/8CorfiE.2GszRfy69::1giSm4Rrtp8Dj2 call System.Object fXt46boBycQ5r.ap5BP::4mjJRc8w(System.Byte[],System.String[],System.Int32) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> ldc.r8 1.087 stloc.0 <null> ldloc.2 <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object fXt46boBycQ5r.Ptt23gHxfQ::5Pjfc4yMg(System.Object) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.3 <null> leave.s IL_00DD: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_5 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00DD: nop nop <null> ret <null>

56e257f481be84feb046cb2a82a89fca (12.28 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙