Suspicious
Suspect

62b4563e05a19ae79b05c4c51cbba5a8

PE Executable
|
MD5: 62b4563e05a19ae79b05c4c51cbba5a8
|
Size: 1.64 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
62b4563e05a19ae79b05c4c51cbba5a8
Sha1
0c02bdfd404bce6724e7b767491b238c16345216
Sha256
f0210da3603f43d66ac5fd9ce665c9bd544cdb66ec47d30b03b8191a6c1c09dc
Sha384
df1570854887fd2096f20203a0b51f2b736c1cb156ea79aa0542f6bc66ae7aae6b85b346d92ff9c1013e953d7192f14b
Sha512
f101a20fabc4e0166254374ec4c1ce4b289c4ed4d2f1e1642e8a25ec731e952a61dfd109bd1f86e8714afc008643ee4d59057370a7c2882198f615deb4ce354a
SSDeep
24576:97/k9mc44Cjl7wrHZd0wlYe0mmvlUfMwEAonf0pTop/J6emd1N7E/Z6I5aO:9zk9L47aNdffeodonf0pTQ/8ei7qZrU
TLSH
CD75025427A59C1AC77D473659A0F1789774CE9BB111C24ABEDD3EE77B2AF000A82383

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
hG.It.resources
us5.ts0.resources
$this.Icon
[NBF]root.IconData
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancel.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
zsS.rsn.resources
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnFind.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnList.Image
[NBF]root.Data
[NBF]root.Data-preview.png
kXi.rXN.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExit.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlue.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PAk.fAY.resources
btnChangePassword.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AAK.uAO.resources
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
e4y.d4p.resources
btnCalculatePrice.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Otopark.csdl
Otopark.msl
Otopark.ssdl
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
智慧停车管理专业版.Properties.Resources.resources
ICS
[NBF]root.Data
[NBF]root.Data-preview.png
Seren
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: yDr.pdb

Module Name

yDr.exe

Full Name

yDr.exe

EntryPoint

System.Void SUo.FU2::kUS()

Scope Name

yDr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yDr

Assembly Version

9.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

447

Main Method

System.Void SUo.FU2::kUS()

Main IL Instruction Count

12

Main IL

br IL_0029: call System.Void System.Windows.Forms.Application::EnableVisualStyles() newobj System.Void kXi.rXN::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0033: ret ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_001F: call System.Void EFv.qF8::MIl() call System.Void EFv.qF8::MIl() br IL_0005: newobj System.Void kXi.rXN::.ctor() call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0014: ldc.i4.0 ret <null>

Module Name

yDr.exe

Full Name

yDr.exe

EntryPoint

System.Void SUo.FU2::kUS()

Scope Name

yDr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yDr

Assembly Version

9.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

447

Main Method

System.Void SUo.FU2::kUS()

Main IL Instruction Count

12

Main IL

br IL_0029: call System.Void System.Windows.Forms.Application::EnableVisualStyles() newobj System.Void kXi.rXN::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0033: ret ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_001F: call System.Void EFv.qF8::MIl() call System.Void EFv.qF8::MIl() br IL_0005: newobj System.Void kXi.rXN::.ctor() call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0014: ldc.i4.0 ret <null>

62b4563e05a19ae79b05c4c51cbba5a8 (1.64 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
hG.It.resources
us5.ts0.resources
$this.Icon
[NBF]root.IconData
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancel.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
zsS.rsn.resources
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnFind.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnList.Image
[NBF]root.Data
[NBF]root.Data-preview.png
kXi.rXN.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExit.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlue.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PAk.fAY.resources
btnChangePassword.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AAK.uAO.resources
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
e4y.d4p.resources
btnCalculatePrice.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Otopark.csdl
Otopark.msl
Otopark.ssdl
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
智慧停车管理专业版.Properties.Resources.resources
ICS
[NBF]root.Data
[NBF]root.Data-preview.png
Seren
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙