Suspicious
Suspect

620c77e892138a779adde4cba3360b61

PE Executable
|
MD5: 620c77e892138a779adde4cba3360b61
|
Size: 745.48 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
620c77e892138a779adde4cba3360b61
Sha1
162bcb8dda69424db57e74de7acfecba84c22c4a
Sha256
881a03adabb46296752648b7bf93ddc112672464b19022e5e4d807cbeb5435ae
Sha384
15533736fdef0b5013aa3cb1b3040c8fa4d7d836b40aa6bc9a483d0b0295b41c5992634af792d5f758f97fc372ef38ac
Sha512
08c13916b440d9f2f8a8e3b1f25b4d0bbaef16b907af72a20ef2a7b79954b0271f07e7c1e1e737077353c1581e3f3959e464fbd02e77c4d403c228990f390287
SSDeep
12288:CFv40pDGXzBafUXFgdvUbcGqqPqptB1k7kJzy6LhV/JH9RbXWjU6S6AChkR:YGXVa8XqdsbcGqmqpzJ/NVRWgGAD
TLSH
32F41215660DE912E9E51BF48CB0D3B35170AECDB017D317A6EDBDEBBA4629029683C0

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PharmacyManager.Properties.Resources.resources
FRsI
[NBF]root.Data
[NBF]root.Data-preview.png
gr
[NBF]root.Data
Informations
Name
Value
Module Name

flZG.exe

Full Name

flZG.exe

EntryPoint

System.Void PharmacyManager.Program::Main()

Scope Name

flZG.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

flZG

Assembly Version

7.8.6.7

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void PharmacyManager.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PharmacyManager.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

flZG.exe

Full Name

flZG.exe

EntryPoint

System.Void PharmacyManager.Program::Main()

Scope Name

flZG.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

flZG

Assembly Version

7.8.6.7

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void PharmacyManager.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PharmacyManager.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
PDB Path

flZG.pdb

620c77e892138a779adde4cba3360b61 (745.48 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PharmacyManager.Properties.Resources.resources
FRsI
[NBF]root.Data
[NBF]root.Data-preview.png
gr
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

flZG.pdb

620c77e892138a779adde4cba3360b61

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙