Suspicious
Suspect

57200d51c3d7dead36dbd9a25d06727e

PE Executable
|
MD5: 57200d51c3d7dead36dbd9a25d06727e
|
Size: 1.18 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
57200d51c3d7dead36dbd9a25d06727e
Sha1
747dc3b0789609473d71c1487773b13ca862e753
Sha256
594d7c9be217c40ab8953121b50db5a7b858df82e0d2b3893598cfa097629037
Sha384
edfd98edabe0023fb5fb849ed27aa242501dac54b61909cc8fbd5952492a463799d30539944f9c52f2968f40e2ee4ec7
Sha512
028a0d40e071397a5f0beabdfe1e172ce8b6faf98bd99fe2d4a9e6fb739e994e46e454a0b821582b5b92422d22c4508a6039a88353dc2d32de83c91a74e97555
SSDeep
24576:Yvnnf4ioDw/CWy67mvHj8Ya1i+2GrrBg5QRvLrDsNznhes+JC3Dri5vMz:4f9ocCWyGmvHqx2GZuSnDsafJC3Drwq
TLSH
9B45E1983241B88FC84789758D58DDF8A5202CABB717DE03F1D72D9FB92D6928E051E3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
kSL
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

KRz.exe

Full Name

KRz.exe

EntryPoint

System.Void Login_And_Register_Form.Program::Main()

Scope Name

KRz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

KRz

Assembly Version

6.3.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

19

Main Method

System.Void Login_And_Register_Form.Program::Main()

Main IL Instruction Count

49

Main IL

nop <null> ldc.i4 774642032 ldc.i4 610708675 xor <null> dup <null> stloc.0 <null> ldc.i4.7 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0099: ret nop <null> ldloc.0 <null> ldc.i4 1287029353 mul <null> ldc.i4 -1468964472 xor <null> br.s IL_0006: ldc.i4 610708675 nop <null> ldc.i4.0 <null> call System.Void Login_And_Register_Form.Program::‬‎‎‎‌​‌‭‌‏‪‫‬‌‪‌‫‍‭‪​‏‎‫‪‏‏‬‮(System.Boolean) ldloc.0 <null> ldc.i4 -1777794938 mul <null> ldc.i4 -1292537037 xor <null> br.s IL_0006: ldc.i4 610708675 call System.Void Login_And_Register_Form.Program::‪‪‪​‫‎‎‌‍‌‌‎‏‍​‌‍‌‎‍‬​‎‫‏‬‬‮‍‮() ldloc.0 <null> ldc.i4 250526270 mul <null> ldc.i4 611732575 xor <null> br.s IL_0006: ldc.i4 610708675 nop <null> ldloc.0 <null> ldc.i4 981664317 mul <null> ldc.i4 -113547857 xor <null> br.s IL_0006: ldc.i4 610708675 newobj System.Void Login_And_Register_Form.registerForm::.ctor() call System.Void Login_And_Register_Form.Program::‏‭‎‌‪‮​​​‌‏‏‎‭‌‬‮​‍‬‌‏​​‌‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 2034666985 mul <null> ldc.i4 -1397515561 xor <null> br IL_0006: ldc.i4 610708675 ret <null>

Module Name

KRz.exe

Full Name

KRz.exe

EntryPoint

System.Void Login_And_Register_Form.Program::Main()

Scope Name

KRz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

KRz

Assembly Version

6.3.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

19

Main Method

System.Void Login_And_Register_Form.Program::Main()

Main IL Instruction Count

49

Main IL

nop <null> ldc.i4 774642032 ldc.i4 610708675 xor <null> dup <null> stloc.0 <null> ldc.i4.7 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0099: ret nop <null> ldloc.0 <null> ldc.i4 1287029353 mul <null> ldc.i4 -1468964472 xor <null> br.s IL_0006: ldc.i4 610708675 nop <null> ldc.i4.0 <null> call System.Void Login_And_Register_Form.Program::‬‎‎‎‌​‌‭‌‏‪‫‬‌‪‌‫‍‭‪​‏‎‫‪‏‏‬‮(System.Boolean) ldloc.0 <null> ldc.i4 -1777794938 mul <null> ldc.i4 -1292537037 xor <null> br.s IL_0006: ldc.i4 610708675 call System.Void Login_And_Register_Form.Program::‪‪‪​‫‎‎‌‍‌‌‎‏‍​‌‍‌‎‍‬​‎‫‏‬‬‮‍‮() ldloc.0 <null> ldc.i4 250526270 mul <null> ldc.i4 611732575 xor <null> br.s IL_0006: ldc.i4 610708675 nop <null> ldloc.0 <null> ldc.i4 981664317 mul <null> ldc.i4 -113547857 xor <null> br.s IL_0006: ldc.i4 610708675 newobj System.Void Login_And_Register_Form.registerForm::.ctor() call System.Void Login_And_Register_Form.Program::‏‭‎‌‪‮​​​‌‏‏‎‭‌‬‮​‍‬‌‏​​‌‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 2034666985 mul <null> ldc.i4 -1397515561 xor <null> br IL_0006: ldc.i4 610708675 ret <null>

57200d51c3d7dead36dbd9a25d06727e (1.18 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
kSL
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙