Suspicious
Suspect

5ac646a17dcee0c649544a10f5493133

PE Executable
MD5: 5ac646a17dcee0c649544a10f5493133
Size: 895.49 KB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
5ac646a17dcee0c649544a10f5493133
Sha1
08f1363ad668f29e81d3fe7550af5319047f757b
Sha256
4e8f402951511d7d3b90b0aa4dac332f1c4df89a032cd773c30374cee5b9d8a0
Sha384
f6a0b369de6680eec34c1b090ccccc1f2e95876ae2c8c08f94cba59114793b2f001b21be7283f66ebf2f19f6077ad7b3
Sha512
0c49c3007644a8b2541570366110f68bf2ba61aa5ed960bd5388fc2eaf41f999fd8578b259dd3e00fa6165cf3774f0cd1f88438e66d036aa4f14915fdfae338d
SSDeep
12288:vV8emrWfSO0EZvyDE1Szn6GXHYqHcvVnaXujgZ/CbmapHIuj0dK1lfwPHa05LxZk:vV6waZ/CK+HRj0dKLfhMNv7PSt
TLSH
6F15E1211E476B89D6AE4BB8C0664C6877F0C90792E3E3176FEC04F05EB3B95CE66446

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Pc0jp3Nx5.Resources.resources
Pc0jp3Nx5.g.resources
e3c12e4dcbb269.Resources.resources
028533510
[NBF]root.Data
028533511
[NBF]root.Data
028533512
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Pc0jp3Nx5

Full Name

Pc0jp3Nx5

EntryPoint

System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF()

Scope Name

Pc0jp3Nx5

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Pc0jp3Nx5

Assembly Version

24.6.6.148

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF()

Main IL Instruction Count

114

Main IL

ldc.i4.3 <null> stloc.3 <null> ldloc.3 <null> switch dnlib.DotNet.Emit.Instruction[] nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::Epe13(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) ldc.i4.0 <null> stloc.3 <null> br.s IL_0002: ldloc.3 nop <null> ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) nop <null> call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::6EzqftZ2W8k(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) nop <null> ldc.i4.2 <null> stloc.3 <null> br.s IL_0002: ldloc.3 newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> br.s IL_006E: br.s IL_0070 br.s IL_0070: ldc.i4.2 ldc.i4.2 <null> stloc.s V_5 ldloc.s V_5 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0090: nop nop <null> newobj System.Void System.Object::.ctor() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Void 3nsNSn.Wa9z8Fgk::yDe5Mk4st1(System.Object) nop <null> leave.s IL_00CC: br.s IL_00CE br.s IL_00A5: br.s IL_00A7 br.s IL_00A7: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.1 <null> nop <null> ldloc.1 <null> nop <null> ldc.i4.5 <null> ldc.i4 1257825286 ldc.i4.3 <null> call System.String 6qeAB5wqyP.Wm8g6Yyrf7Ca::eHp6Fa2y(System.Int32,System.Int32,System.Int32) call System.Void Qno0g6mZ.9KnaLg7::9Fjaa(System.Exception,System.String) br.s IL_00C4: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00CC: br.s IL_00CE br.s IL_00CE: ldc.i4.2 ldc.i4.2 <null> stloc.s V_7 ldloc.s V_7 switch dnlib.DotNet.Emit.Instruction[] br.s IL_00EE: leave.s IL_0146 leave.s IL_0146: br.s IL_0148 br.s IL_00F2: ldc.i4.3 ldc.i4.3 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0116: nop nop <null> ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::Epe13(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) call System.Void System.Windows.Forms.Application::remove_ThreadException(System.Threading.ThreadExceptionEventHandler) nop <null> call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::6EzqftZ2W8k(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::remove_UnhandledException(System.UnhandledExceptionEventHandler) ldc.i4.5 <null> stloc.s V_9 br.s IL_00F5: ldloc.s V_9 nop <null> endfinally <null> br.s IL_0148: ldc.i4.2 ldc.i4.2 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0168: nop nop <null> ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4.s 83 ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4.s 83 ldelem.i4 <null> ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4 128 ldelem.i4 <null> and <null> ldc.i4.4 <null> and <null> stelem.i4 <null> ret <null> ldtoken System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF() pop <null> ret <null>

Module Name

Pc0jp3Nx5

Full Name

Pc0jp3Nx5

EntryPoint

System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF()

Scope Name

Pc0jp3Nx5

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Pc0jp3Nx5

Assembly Version

24.6.6.148

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF()

Main IL Instruction Count

114

Main IL

ldc.i4.3 <null> stloc.3 <null> ldloc.3 <null> switch dnlib.DotNet.Emit.Instruction[] nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::Epe13(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) ldc.i4.0 <null> stloc.3 <null> br.s IL_0002: ldloc.3 nop <null> ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) nop <null> call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::6EzqftZ2W8k(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) nop <null> ldc.i4.2 <null> stloc.3 <null> br.s IL_0002: ldloc.3 newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> br.s IL_006E: br.s IL_0070 br.s IL_0070: ldc.i4.2 ldc.i4.2 <null> stloc.s V_5 ldloc.s V_5 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0090: nop nop <null> newobj System.Void System.Object::.ctor() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Void 3nsNSn.Wa9z8Fgk::yDe5Mk4st1(System.Object) nop <null> leave.s IL_00CC: br.s IL_00CE br.s IL_00A5: br.s IL_00A7 br.s IL_00A7: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.1 <null> nop <null> ldloc.1 <null> nop <null> ldc.i4.5 <null> ldc.i4 1257825286 ldc.i4.3 <null> call System.String 6qeAB5wqyP.Wm8g6Yyrf7Ca::eHp6Fa2y(System.Int32,System.Int32,System.Int32) call System.Void Qno0g6mZ.9KnaLg7::9Fjaa(System.Exception,System.String) br.s IL_00C4: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00CC: br.s IL_00CE br.s IL_00CE: ldc.i4.2 ldc.i4.2 <null> stloc.s V_7 ldloc.s V_7 switch dnlib.DotNet.Emit.Instruction[] br.s IL_00EE: leave.s IL_0146 leave.s IL_0146: br.s IL_0148 br.s IL_00F2: ldc.i4.3 ldc.i4.3 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0116: nop nop <null> ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::Epe13(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) call System.Void System.Windows.Forms.Application::remove_ThreadException(System.Threading.ThreadExceptionEventHandler) nop <null> call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void Qno0g6mZ.9KnaLg7::6EzqftZ2W8k(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::remove_UnhandledException(System.UnhandledExceptionEventHandler) ldc.i4.5 <null> stloc.s V_9 br.s IL_00F5: ldloc.s V_9 nop <null> endfinally <null> br.s IL_0148: ldc.i4.2 ldc.i4.2 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0168: nop nop <null> ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4.s 83 ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4.s 83 ldelem.i4 <null> ldsfld System.Int32[] pd4Q0rTqy7y.2mpJyG5qrs::Le7ed ldc.i4 128 ldelem.i4 <null> and <null> ldc.i4.4 <null> and <null> stelem.i4 <null> ret <null> ldtoken System.Void Qno0g6mZ.9KnaLg7::7ywJf_P38KqqF() pop <null> ret <null>

5ac646a17dcee0c649544a10f5493133 (895.49 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙