Suspicious
Suspect

6048cd4c221567cfc7890d718c6fa74e

PE Executable
|
MD5: 6048cd4c221567cfc7890d718c6fa74e
|
Size: 816.13 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
6048cd4c221567cfc7890d718c6fa74e
Sha1
df944a34c391bbff0f151b1f89cff90e4be86bb1
Sha256
ae91525ecd727e79110dcc98c87e4e30402fbd47f95a2b153e7eda2da97a15fe
Sha384
0341a83e2af37fdb7fa0558c7adddf29d8497de28933f20e29ce9d15eb022e5b3e0f477ae2f2ee52634e6669c9fc886d
Sha512
5b715bf47401050405b6abd62090997f09ad25207f6d176519e0929835050f3b8d98ff46a878f2f1efbe1fc8d5a55027ee508a5ef9fe8b2942b3bae3afb57877
SSDeep
24576:eGB8W4iyZMVUmXF5LYibOHIlSxsaSGpli4ZXRf:eGBMiyZMVUmXb5OISxjLf
TLSH
DA0523740BA5EA12E9A913F20873EAB403740D5FC132D74A4BDFDDE7B81B71265943A1

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberLink.FormSelecteurNiveau.resources
NumberLink.Properties.Resources.resources
CyabFe
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: xtJxKQ.pdb

Module Name

xtJxKQ.exe

Full Name

xtJxKQ.exe

EntryPoint

System.Void NumberLink.Program::Main()

Scope Name

xtJxKQ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xtJxKQ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

56

Main Method

System.Void NumberLink.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NumberLink.FormSelecteurNiveau::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

xtJxKQ.exe

Full Name

xtJxKQ.exe

EntryPoint

System.Void NumberLink.Program::Main()

Scope Name

xtJxKQ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xtJxKQ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

56

Main Method

System.Void NumberLink.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NumberLink.FormSelecteurNiveau::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

6048cd4c221567cfc7890d718c6fa74e (816.13 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberLink.FormSelecteurNiveau.resources
NumberLink.Properties.Resources.resources
CyabFe
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙