Suspicious
Suspect

643981b59063b00424f8ecce2477828c

PE Executable
|
MD5: 643981b59063b00424f8ecce2477828c
|
Size: 743.42 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
643981b59063b00424f8ecce2477828c
Sha1
ccd3f2d9c6a9dfb03c0cd15a519e6c5324516b55
Sha256
728e559497f67d11db44bee08e80408e40612f122a096e55e5923b59976f82f2
Sha384
72380ab8081a3f3afcac7dd2879c71fe998a81c9441d4589d602ca528eca1f531b56c1e52022f5602c61a5112e2eb529
Sha512
71ce62cfacbfa7c50f2596534cf9de2f7699a102eee4a55d0213af3d21903c7415e7599dcda233d79befa4047643a9086a2b290bb1d83fb8d69ca5e47a6a4af9
SSDeep
12288:DE2LOwUN4jHrUL13CirC0hmp+cIdbFVDJrk5chA9dlkHD52MXfy+E/Ij9UfuO5RV:DE2BXHrK32QtFdJrycm9dqHtq+E/UUfv
TLSH
80F412502A56DA13C49267F4ADB1D3F813E8AD9EAC01D34B4EE9BDDB3C32714A9442D3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsContacts.AddEditContactForm.resources
WindowsContacts.Properties.Resources.resources
KOp
[NBF]root.Data
VIB
[NBF]root.Data
[NBF]root.Data-preview.png
kupa
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ORC.pdb

Module Name

ORC.exe

Full Name

ORC.exe

EntryPoint

System.Void WindowsContacts.Program::Main()

Scope Name

ORC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ORC

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

208

Main Method

System.Void WindowsContacts.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsContacts.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

ORC.exe

Full Name

ORC.exe

EntryPoint

System.Void WindowsContacts.Program::Main()

Scope Name

ORC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ORC

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

208

Main Method

System.Void WindowsContacts.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsContacts.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

643981b59063b00424f8ecce2477828c (743.42 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙