Suspicious
Suspect

61e28f4ff02967cb647563eae9d00240

PE Executable
|
MD5: 61e28f4ff02967cb647563eae9d00240
|
Size: 5.59 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
61e28f4ff02967cb647563eae9d00240
Sha1
607939122d81561cb9f30f2e2597c43fa8429ac6
Sha256
e53905be786890e707d3afe844cbb853b3b5db4f52768df923ac867a2659c3b1
Sha384
b03c8531cb3e3cb8085d8ddb1ba6de3452f5d47e01e1904d418d47b4ff7cd7e74fa6e1fee171660f5ad0ce76e47b5452
Sha512
4a9a08af4ff96d006fee782fb6317739cdc0796bfc8d1134e7b6a037ff5a111dea553f1c84cbfed020e353ff505882e0134c6aa7091288633860a5f5a30df910
SSDeep
98304:JPuQ/2a9Or4cW+PvkNDHmjQq32yeDGWJ:dWagr4cW+P8SQwnW
TLSH
1B46121632C28E54E67F577484B9C98267F8BD4B6B31CB1D378B13EC5F0229A6612723

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Cerkagofan.habadegar
1Pemf7Ka.Resources.resources
090a346990f095.Resources.resources
56b7d6ae0
[NBF]root.Data
56b7d6ae1
[NBF]root.Data
56b7d6ae10
[NBF]root.Data
56b7d6ae100
[NBF]root.Data
56b7d6ae101
[NBF]root.Data
56b7d6ae102
[NBF]root.Data
56b7d6ae103
[NBF]root.Data
56b7d6ae104
[NBF]root.Data
56b7d6ae105
[NBF]root.Data
56b7d6ae106
[NBF]root.Data
56b7d6ae107
[NBF]root.Data
56b7d6ae108
[NBF]root.Data
56b7d6ae109
[NBF]root.Data
56b7d6ae11
[NBF]root.Data
56b7d6ae110
[NBF]root.Data
56b7d6ae111
[NBF]root.Data
56b7d6ae112
[NBF]root.Data
56b7d6ae113
[NBF]root.Data
56b7d6ae114
[NBF]root.Data
56b7d6ae115
[NBF]root.Data
56b7d6ae116
[NBF]root.Data
56b7d6ae117
[NBF]root.Data
56b7d6ae118
[NBF]root.Data
56b7d6ae119
[NBF]root.Data
56b7d6ae12
[NBF]root.Data
56b7d6ae120
[NBF]root.Data
56b7d6ae121
[NBF]root.Data
56b7d6ae122
[NBF]root.Data
56b7d6ae123
[NBF]root.Data
56b7d6ae124
[NBF]root.Data
56b7d6ae125
[NBF]root.Data
56b7d6ae126
[NBF]root.Data
56b7d6ae127
[NBF]root.Data
56b7d6ae128
[NBF]root.Data
56b7d6ae129
[NBF]root.Data
56b7d6ae13
[NBF]root.Data
56b7d6ae130
[NBF]root.Data
56b7d6ae131
[NBF]root.Data
56b7d6ae132
[NBF]root.Data
56b7d6ae133
[NBF]root.Data
56b7d6ae134
[NBF]root.Data
56b7d6ae135
[NBF]root.Data
56b7d6ae136
[NBF]root.Data
56b7d6ae137
[NBF]root.Data
56b7d6ae138
[NBF]root.Data
56b7d6ae139
[NBF]root.Data
56b7d6ae14
[NBF]root.Data
56b7d6ae140
[NBF]root.Data
56b7d6ae141
[NBF]root.Data
56b7d6ae142
[NBF]root.Data
56b7d6ae143
[NBF]root.Data
56b7d6ae144
[NBF]root.Data
56b7d6ae145
[NBF]root.Data
56b7d6ae146
[NBF]root.Data
56b7d6ae147
[NBF]root.Data
56b7d6ae148
[NBF]root.Data
56b7d6ae149
[NBF]root.Data
56b7d6ae15
[NBF]root.Data
56b7d6ae150
[NBF]root.Data
56b7d6ae151
[NBF]root.Data
56b7d6ae152
[NBF]root.Data
56b7d6ae153
[NBF]root.Data
56b7d6ae154
[NBF]root.Data
56b7d6ae155
[NBF]root.Data
56b7d6ae156
[NBF]root.Data
56b7d6ae157
[NBF]root.Data
56b7d6ae158
[NBF]root.Data
56b7d6ae159
[NBF]root.Data
56b7d6ae16
[NBF]root.Data
56b7d6ae160
[NBF]root.Data
56b7d6ae161
[NBF]root.Data
56b7d6ae162
[NBF]root.Data
56b7d6ae163
[NBF]root.Data
56b7d6ae164
[NBF]root.Data
56b7d6ae165
[NBF]root.Data
56b7d6ae166
[NBF]root.Data
56b7d6ae167
[NBF]root.Data
56b7d6ae168
[NBF]root.Data
56b7d6ae169
[NBF]root.Data
56b7d6ae17
[NBF]root.Data
56b7d6ae170
[NBF]root.Data
56b7d6ae171
[NBF]root.Data
56b7d6ae172
[NBF]root.Data
56b7d6ae173
[NBF]root.Data
56b7d6ae174
[NBF]root.Data
56b7d6ae175
[NBF]root.Data
56b7d6ae176
[NBF]root.Data
56b7d6ae177
[NBF]root.Data
56b7d6ae178
[NBF]root.Data
56b7d6ae179
[NBF]root.Data
56b7d6ae18
[NBF]root.Data
56b7d6ae180
[NBF]root.Data
56b7d6ae181
[NBF]root.Data
56b7d6ae182
[NBF]root.Data
56b7d6ae183
[NBF]root.Data
56b7d6ae184
[NBF]root.Data
56b7d6ae185
[NBF]root.Data
56b7d6ae186
[NBF]root.Data
56b7d6ae187
[NBF]root.Data
56b7d6ae188
[NBF]root.Data
56b7d6ae189
[NBF]root.Data
56b7d6ae19
[NBF]root.Data
56b7d6ae190
[NBF]root.Data
56b7d6ae191
[NBF]root.Data
56b7d6ae192
[NBF]root.Data
56b7d6ae193
[NBF]root.Data
56b7d6ae194
[NBF]root.Data
56b7d6ae195
[NBF]root.Data
56b7d6ae196
[NBF]root.Data
56b7d6ae197
[NBF]root.Data
56b7d6ae198
[NBF]root.Data
56b7d6ae199
[NBF]root.Data
56b7d6ae2
[NBF]root.Data
56b7d6ae20
[NBF]root.Data
56b7d6ae200
[NBF]root.Data
56b7d6ae201
[NBF]root.Data
56b7d6ae202
[NBF]root.Data
56b7d6ae203
[NBF]root.Data
56b7d6ae204
[NBF]root.Data
56b7d6ae205
[NBF]root.Data
56b7d6ae206
[NBF]root.Data
56b7d6ae207
[NBF]root.Data
56b7d6ae208
[NBF]root.Data
56b7d6ae209
[NBF]root.Data
56b7d6ae21
[NBF]root.Data
56b7d6ae210
[NBF]root.Data
56b7d6ae211
[NBF]root.Data
56b7d6ae212
[NBF]root.Data
56b7d6ae213
[NBF]root.Data
56b7d6ae214
[NBF]root.Data
56b7d6ae215
[NBF]root.Data
56b7d6ae216
[NBF]root.Data
56b7d6ae217
[NBF]root.Data
56b7d6ae218
[NBF]root.Data
56b7d6ae219
[NBF]root.Data
56b7d6ae22
[NBF]root.Data
56b7d6ae220
[NBF]root.Data
56b7d6ae221
[NBF]root.Data
56b7d6ae222
[NBF]root.Data
56b7d6ae223
[NBF]root.Data
56b7d6ae224
[NBF]root.Data
56b7d6ae225
[NBF]root.Data
56b7d6ae226
[NBF]root.Data
56b7d6ae227
[NBF]root.Data
56b7d6ae228
[NBF]root.Data
56b7d6ae229
[NBF]root.Data
56b7d6ae23
[NBF]root.Data
56b7d6ae230
[NBF]root.Data
56b7d6ae231
[NBF]root.Data
56b7d6ae232
[NBF]root.Data
56b7d6ae233
[NBF]root.Data
56b7d6ae234
[NBF]root.Data
56b7d6ae235
[NBF]root.Data
56b7d6ae236
[NBF]root.Data
56b7d6ae237
[NBF]root.Data
56b7d6ae238
[NBF]root.Data
56b7d6ae239
[NBF]root.Data
56b7d6ae24
[NBF]root.Data
56b7d6ae240
[NBF]root.Data
56b7d6ae241
[NBF]root.Data
56b7d6ae242
[NBF]root.Data
56b7d6ae243
[NBF]root.Data
56b7d6ae244
[NBF]root.Data
56b7d6ae245
[NBF]root.Data
56b7d6ae246
[NBF]root.Data
56b7d6ae247
[NBF]root.Data
56b7d6ae248
[NBF]root.Data
56b7d6ae249
[NBF]root.Data
56b7d6ae25
[NBF]root.Data
56b7d6ae250
[NBF]root.Data
56b7d6ae251
[NBF]root.Data
56b7d6ae252
[NBF]root.Data
56b7d6ae253
[NBF]root.Data
56b7d6ae254
[NBF]root.Data
56b7d6ae255
[NBF]root.Data
56b7d6ae256
[NBF]root.Data
56b7d6ae257
[NBF]root.Data
56b7d6ae258
[NBF]root.Data
56b7d6ae259
[NBF]root.Data
56b7d6ae26
[NBF]root.Data
56b7d6ae260
[NBF]root.Data
56b7d6ae261
[NBF]root.Data
56b7d6ae262
[NBF]root.Data
56b7d6ae263
[NBF]root.Data
56b7d6ae264
[NBF]root.Data
56b7d6ae265
[NBF]root.Data
56b7d6ae266
[NBF]root.Data
56b7d6ae267
[NBF]root.Data
56b7d6ae268
[NBF]root.Data
56b7d6ae269
[NBF]root.Data
56b7d6ae27
[NBF]root.Data
56b7d6ae270
[NBF]root.Data
56b7d6ae271
[NBF]root.Data
56b7d6ae272
[NBF]root.Data
56b7d6ae273
[NBF]root.Data
56b7d6ae274
[NBF]root.Data
56b7d6ae275
[NBF]root.Data
56b7d6ae276
[NBF]root.Data
56b7d6ae277
[NBF]root.Data
56b7d6ae278
[NBF]root.Data
56b7d6ae279
[NBF]root.Data
56b7d6ae28
[NBF]root.Data
56b7d6ae280
[NBF]root.Data
56b7d6ae281
[NBF]root.Data
56b7d6ae282
[NBF]root.Data
56b7d6ae29
[NBF]root.Data
56b7d6ae3
[NBF]root.Data
56b7d6ae30
[NBF]root.Data
56b7d6ae31
[NBF]root.Data
56b7d6ae32
[NBF]root.Data
56b7d6ae33
[NBF]root.Data
56b7d6ae34
[NBF]root.Data
56b7d6ae35
[NBF]root.Data
56b7d6ae36
[NBF]root.Data
56b7d6ae37
[NBF]root.Data
56b7d6ae38
[NBF]root.Data
56b7d6ae39
[NBF]root.Data
56b7d6ae4
[NBF]root.Data
56b7d6ae40
[NBF]root.Data
56b7d6ae41
[NBF]root.Data
56b7d6ae42
[NBF]root.Data
56b7d6ae43
[NBF]root.Data
56b7d6ae44
[NBF]root.Data
56b7d6ae45
[NBF]root.Data
56b7d6ae46
[NBF]root.Data
56b7d6ae47
[NBF]root.Data
56b7d6ae48
[NBF]root.Data
56b7d6ae49
[NBF]root.Data
56b7d6ae5
[NBF]root.Data
56b7d6ae50
[NBF]root.Data
56b7d6ae51
[NBF]root.Data
56b7d6ae52
[NBF]root.Data
56b7d6ae53
[NBF]root.Data
56b7d6ae54
[NBF]root.Data
56b7d6ae55
[NBF]root.Data
56b7d6ae56
[NBF]root.Data
56b7d6ae57
[NBF]root.Data
56b7d6ae58
[NBF]root.Data
56b7d6ae59
[NBF]root.Data
56b7d6ae6
[NBF]root.Data
56b7d6ae60
[NBF]root.Data
56b7d6ae61
[NBF]root.Data
56b7d6ae62
[NBF]root.Data
56b7d6ae63
[NBF]root.Data
56b7d6ae64
[NBF]root.Data
56b7d6ae65
[NBF]root.Data
56b7d6ae66
[NBF]root.Data
56b7d6ae67
[NBF]root.Data
56b7d6ae68
[NBF]root.Data
56b7d6ae69
[NBF]root.Data
56b7d6ae7
[NBF]root.Data
56b7d6ae70
[NBF]root.Data
56b7d6ae71
[NBF]root.Data
56b7d6ae72
[NBF]root.Data
56b7d6ae73
[NBF]root.Data
56b7d6ae74
[NBF]root.Data
56b7d6ae75
[NBF]root.Data
56b7d6ae76
[NBF]root.Data
56b7d6ae77
[NBF]root.Data
56b7d6ae78
[NBF]root.Data
56b7d6ae79
[NBF]root.Data
56b7d6ae8
[NBF]root.Data
56b7d6ae80
[NBF]root.Data
56b7d6ae81
[NBF]root.Data
56b7d6ae82
[NBF]root.Data
56b7d6ae83
[NBF]root.Data
56b7d6ae84
[NBF]root.Data
56b7d6ae85
[NBF]root.Data
56b7d6ae86
[NBF]root.Data
56b7d6ae87
[NBF]root.Data
56b7d6ae88
[NBF]root.Data
56b7d6ae89
[NBF]root.Data
56b7d6ae9
[NBF]root.Data
56b7d6ae90
[NBF]root.Data
56b7d6ae91
[NBF]root.Data
56b7d6ae92
[NBF]root.Data
56b7d6ae93
[NBF]root.Data
56b7d6ae94
[NBF]root.Data
56b7d6ae95
[NBF]root.Data
56b7d6ae96
[NBF]root.Data
56b7d6ae97
[NBF]root.Data
56b7d6ae98
[NBF]root.Data
56b7d6ae99
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

1Pemf7Ka

Full Name

1Pemf7Ka

EntryPoint

System.Void 1Pemf7Ka.aLz51gnMFc/9PreCi2wt1.9Jdzr5Wskk3::nGr48jDdC7my3b()

Scope Name

1Pemf7Ka

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

1Pemf7Ka

Assembly Version

8.19.28.284

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

993

Main Method

System.Void 1Pemf7Ka.aLz51gnMFc/9PreCi2wt1.9Jdzr5Wskk3::nGr48jDdC7my3b()

Main IL Instruction Count

91

Main IL

nop <null> nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 20 stloc.1 <null> newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.2 <null> ldloc.1 <null> stloc.s V_7 ldc.i4.1 <null> stloc.s V_8 br.s IL_002E: ldloc.s V_8 ldloc.2 <null> ldloc.s V_8 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_8 ldc.i4.1 <null> add.ovf <null> stloc.s V_8 ldloc.s V_8 ldloc.s V_7 ble.s IL_001F: ldloc.2 ldstr FacilityOptima.Core stloc.3 <null> ldstr 2.4.1 stloc.s V_4 call System.Guid System.Guid::NewGuid() stloc.s V_9 ldloca.s V_9 ldstr N call System.String System.Guid::ToString(System.String) ldc.i4.0 <null> ldc.i4.s 12 callvirt System.String System.String::Substring(System.Int32,System.Int32) stloc.s V_5 ldloc.2 <null> callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.1 <null> ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_10 ldloc.s V_10 brfalse.s IL_0078: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> nop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr FacilityOptima ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_11 ldloc.s V_11 brfalse.s IL_00AA: nop ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr habadegar call System.Void 1Pemf7Ka.Sm2bz6fJogT8Mm/qLm5f1AzYg4r.9gwKxHn3C8gy::7Nbwj0iW(System.String) nop <null> call System.Void System.GC::Collect() nop <null> call System.Void System.GC::WaitForPendingFinalizers() nop <null> leave.s IL_00E0: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E0: nop nop <null> ret <null>

Module Name

1Pemf7Ka

Full Name

1Pemf7Ka

EntryPoint

System.Void 1Pemf7Ka.aLz51gnMFc/9PreCi2wt1.9Jdzr5Wskk3::nGr48jDdC7my3b()

Scope Name

1Pemf7Ka

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

1Pemf7Ka

Assembly Version

8.19.28.284

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

993

Main Method

System.Void 1Pemf7Ka.aLz51gnMFc/9PreCi2wt1.9Jdzr5Wskk3::nGr48jDdC7my3b()

Main IL Instruction Count

91

Main IL

nop <null> nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 20 stloc.1 <null> newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.2 <null> ldloc.1 <null> stloc.s V_7 ldc.i4.1 <null> stloc.s V_8 br.s IL_002E: ldloc.s V_8 ldloc.2 <null> ldloc.s V_8 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_8 ldc.i4.1 <null> add.ovf <null> stloc.s V_8 ldloc.s V_8 ldloc.s V_7 ble.s IL_001F: ldloc.2 ldstr FacilityOptima.Core stloc.3 <null> ldstr 2.4.1 stloc.s V_4 call System.Guid System.Guid::NewGuid() stloc.s V_9 ldloca.s V_9 ldstr N call System.String System.Guid::ToString(System.String) ldc.i4.0 <null> ldc.i4.s 12 callvirt System.String System.String::Substring(System.Int32,System.Int32) stloc.s V_5 ldloc.2 <null> callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.1 <null> ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_10 ldloc.s V_10 brfalse.s IL_0078: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> nop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr FacilityOptima ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_11 ldloc.s V_11 brfalse.s IL_00AA: nop ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr habadegar call System.Void 1Pemf7Ka.Sm2bz6fJogT8Mm/qLm5f1AzYg4r.9gwKxHn3C8gy::7Nbwj0iW(System.String) nop <null> call System.Void System.GC::Collect() nop <null> call System.Void System.GC::WaitForPendingFinalizers() nop <null> leave.s IL_00E0: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E0: nop nop <null> ret <null>

61e28f4ff02967cb647563eae9d00240 (5.59 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙