Suspicious
Suspect

60de389f7de9d3dc7489f9413a3fb69c

PE Executable
|
MD5: 60de389f7de9d3dc7489f9413a3fb69c
|
Size: 854.02 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
60de389f7de9d3dc7489f9413a3fb69c
Sha1
844969a2baa8ea04d832998c2169efca41dacdb5
Sha256
4f9df0124b362959024305dead04b4637ff379d2cc1b94962fddc9acd039bad4
Sha384
dc253acea9535d09bddd64f938eabc56abbc8c4588f8266fbe53b40f664113051555ba1d8eafd8c4aadfa96e8f3ceab6
Sha512
a58cad1af16f6b2c0c29c717aa6e7aef6af66d119e4f90981e103b9fdf3bcb84a4b964d0023692bc70e3eba927760ad70f4f8a11bb00bb4e186dd40e2cd3da18
SSDeep
12288:4SoGKvxPh1lnV/F5fXw6o1+itRYd/U6E5aXuKFT2zBsb34bcWqJk0FSR+CcFAYEr:BoGcxpDV/pykbEQXHSz0J42A
TLSH
7105DFAC3254B49FC463CE728D60EE74A6607C6A9717C20391E71CAFB91D687DE142E3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
Chhn
[NBF]root.Data
[NBF]root.Data-preview.png
Teacher
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

uAlA.exe

Full Name

uAlA.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

uAlA.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

uAlA

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

25

Main IL

nop <null> call System.Void ClipboardAnalyzer.Program::‮‏‬‬​‭‎‌‎‌‏‪‮‫‏‫‪‪‪‏‬‌‌‬​‬‭‭‌‮() nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‎​‌‭​‭‮‏​‮‌‍​‪‌​‬‍‮​‏‭‬‮(System.Boolean) ldc.i4 1696633408 ldc.i4 1559286998 xor <null> dup <null> stloc.0 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_004A: ret nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‭‏‌‮‎‬‪‬‫​‪‪‬‏‪‪‫‌‬‮‍‍​‮(System.Windows.Forms.Form) nop <null> ldloc.0 <null> ldc.i4 -859962074 mul <null> ldc.i4 -180056936 xor <null> br.s IL_0012: ldc.i4 1559286998 ret <null>

Module Name

uAlA.exe

Full Name

uAlA.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

uAlA.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

uAlA

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

25

Main IL

nop <null> call System.Void ClipboardAnalyzer.Program::‮‏‬‬​‭‎‌‎‌‏‪‮‫‏‫‪‪‪‏‬‌‌‬​‬‭‭‌‮() nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‎​‌‭​‭‮‏​‮‌‍​‪‌​‬‍‮​‏‭‬‮(System.Boolean) ldc.i4 1696633408 ldc.i4 1559286998 xor <null> dup <null> stloc.0 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_004A: ret nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‭‏‌‮‎‬‪‬‫​‪‪‬‏‪‪‫‌‬‮‍‍​‮(System.Windows.Forms.Form) nop <null> ldloc.0 <null> ldc.i4 -859962074 mul <null> ldc.i4 -180056936 xor <null> br.s IL_0012: ldc.i4 1559286998 ret <null>

60de389f7de9d3dc7489f9413a3fb69c (854.02 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙