Suspicious
Suspect

5d14a18e3866d2473923562c7d54627a

PE Executable
|
MD5: 5d14a18e3866d2473923562c7d54627a
|
Size: 1.44 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
5d14a18e3866d2473923562c7d54627a
Sha1
3bd9fcf6231a5d2f66a57454785c7e05b3bc4138
Sha256
528d68f078493c4e45e52387fcf4e69830d0ef9052e7c2ba14a4437b08c594e3
Sha384
23c4522342f2a6b7f9f1c5bec80bf0e411e8e12c740ec017d445e4f5d1e1fccf49e3e59cf545f5a72dcd5e177feec2ee
Sha512
4dc6691a893181d603013c3d5c841233921447c462b8d97139c11ab4d2f8c69fc9ec421c3debdf4f08f9a7e8d94cfde907a3cdfdeab6a17e73e357d141294324
SSDeep
24576:h/Vx8nAd+KSVAMtozRPqeCKLEI607cVI1rdQBnrTe7canR//ycRhf80tl/:h/Vx8yqszYI6AcVGBmryzByGEaZ
TLSH
C36533518060A7AEC7CB25B04E3FD9C750A59B60B57976061D6B0CC11FE9C8EFA1B372

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Tjvdoagke.Properties.Resources.resources
Rjxhtpn
Informations
Name
Value
Module Name

Nowe zamówienie.exe

Full Name

Nowe zamówienie.exe

EntryPoint

System.Void Tjvdoagke.Lqxnpsrzft::Main()

Scope Name

Nowe zamówienie.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Nowe zamówienie

Assembly Version

1.0.2125.23747

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

6

Main Method

System.Void Tjvdoagke.Lqxnpsrzft::Main()

Main IL Instruction Count

11

Main IL

ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0 dup <null> brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>) pop <null> ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9 ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0 call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>) ret <null>

Module Name

Nowe zamówienie.exe

Full Name

Nowe zamówienie.exe

EntryPoint

System.Void Tjvdoagke.Lqxnpsrzft::Main()

Scope Name

Nowe zamówienie.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Nowe zamówienie

Assembly Version

1.0.2125.23747

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

6

Main Method

System.Void Tjvdoagke.Lqxnpsrzft::Main()

Main IL Instruction Count

11

Main IL

ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0 dup <null> brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>) pop <null> ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9 ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0 call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>) ret <null>

5d14a18e3866d2473923562c7d54627a (1.44 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙