Suspicious
Suspect

6373654f6b3afd25cd3eaace5b958d56

PE Executable
|
MD5: 6373654f6b3afd25cd3eaace5b958d56
|
Size: 772.1 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
6373654f6b3afd25cd3eaace5b958d56
Sha1
02566a10c7c2172749bd84d685cf28a15206647b
Sha256
4bc7c3ee641390b78c356aef216d987fa7eba48192678f73048561762b11a5a9
Sha384
7aa2be9184629e0a5667a004579e77efff84b835ef56f0b748a81c57501cb90e37ecb77c893780a290091f5619a875ef
Sha512
4523a922e08b8be58917000769acdec0d58a47d7c445e0883d11ff9186fdab498a835d3b5bb783fe2ec416a2a0a764be12d328e389843e01eeef3fea81532d3b
SSDeep
12288:LRWJfRec0YijDDOvJoRyl4b2kYokZy3/v1lr7YqDAcwsjGpt5W0LtBAKbbctSwUg:epGjDgJVG/YVZyvvnYqusARjbXwUDJ
TLSH
7AF41254226AEF13C0930BF41970E2B067B9ADC9A022D6175FEA3EDFFD16B850945393

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RM_Colocar.FrmMenu.resources
$this.Icon
[NBF]root.IconData
Capo
[NBF]root.Data
menuStrip1.TrayLocation
RM_Colocar.Properties.Resources.resources
fbvI
[NBF]root.Data
[NBF]root.Data-preview.png
x
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmCaixa.resources
RM_Colocar.Views.FrmCidades.resources
btnAlterar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancelar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExcluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnIncluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnPesquisa.Image
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmClientes.resources
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\XEeWETnKlN\src\obj\Debug\zvXA.pdb

Module Name

zvXA.exe

Full Name

zvXA.exe

EntryPoint

System.Void RM_Colocar.Program::Main()

Scope Name

zvXA.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zvXA

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

234

Main Method

System.Void RM_Colocar.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void RM_Colocar.FrmMenu::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

zvXA.exe

Full Name

zvXA.exe

EntryPoint

System.Void RM_Colocar.Program::Main()

Scope Name

zvXA.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zvXA

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

234

Main Method

System.Void RM_Colocar.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void RM_Colocar.FrmMenu::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

6373654f6b3afd25cd3eaace5b958d56 (772.1 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RM_Colocar.FrmMenu.resources
$this.Icon
[NBF]root.IconData
Capo
[NBF]root.Data
menuStrip1.TrayLocation
RM_Colocar.Properties.Resources.resources
fbvI
[NBF]root.Data
[NBF]root.Data-preview.png
x
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmCaixa.resources
RM_Colocar.Views.FrmCidades.resources
btnAlterar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancelar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExcluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnIncluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnPesquisa.Image
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmClientes.resources
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙