Suspicious
Suspect

60475d8eca79afa50ddda28584df7269

PE Executable
|
MD5: 60475d8eca79afa50ddda28584df7269
|
Size: 502.79 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
60475d8eca79afa50ddda28584df7269
Sha1
070a9f5eba4f2de879d49550eb9c30ea3d3cc5fd
Sha256
b1298b37ed1013fa522241867cdb94d31eaab112d3923040efd29648abf9b238
Sha384
3251bcc991c83b78a77182016e5f0ebca3232da74d027033b972c9b5219777cca89228ec6a25f820b325d8baad216101
Sha512
ed7341e6fbda34cd9194a71dc5782f17b43dec4d2cac6c5fe97fde88c93b17bd9fbc0b8f53af4efc43bd1accb1a7713fd11b0120447f78defa0e8129e0afd1bb
SSDeep
12288:cZ50OWLJE3bbU8lDdvHxHS1q1+hf16/ikR:2ci3ffxPMq1+CR
TLSH
3FB4018A225BCA03D6B117B05CF1E37557B86FC9F420C3165AE9ADDB386A7607C81393
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberBaseConverter.MainForm.resources
NumberBaseConverter.Properties.Resources.resources
KS
[NBF]root.Data
tKHS
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x77600 size 13832 bytes

Info

PDB Path: yWEm.pdb

Module Name

yWEm.exe

Full Name

yWEm.exe

EntryPoint

System.Void NumberBaseConverter.Program::Main()

Scope Name

yWEm.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yWEm

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

131

Main Method

System.Void NumberBaseConverter.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NumberBaseConverter.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

60475d8eca79afa50ddda28584df7269 (502.79 KB)
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberBaseConverter.MainForm.resources
NumberBaseConverter.Properties.Resources.resources
KS
[NBF]root.Data
tKHS
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙