Suspicious
Suspect

6674ee0be1fe99e615c84ed2a1bb72b0

PE Executable
|
MD5: 6674ee0be1fe99e615c84ed2a1bb72b0
|
Size: 5.59 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
6674ee0be1fe99e615c84ed2a1bb72b0
Sha1
a96765dffd11d4e4b0e9ded2fc9d8c96458038ed
Sha256
16b2789f485c9dd68380887a499dac1c14dd66cc87628133b8e08c1fef1c1a41
Sha384
3eadbe4f73d3bee89dd01ce60c241ef581476f7a486f6bbafda38547561b7b0bfea5f54694939f397ea89efcb38e7bcc
Sha512
c65d931de31b92f3fd801d6a26dd3a75dccdfb90a3f2fc1c969c6db84b7b7f16ba10bc0a2da7bd1c6000628c411951c5aea2d2f4cdcd1e8bc7706374c40774d7
SSDeep
98304:ddRhXUQ/2AU1nDuycv7XW2XBQq32yeDGWJ1:ddRhXkAanDuycjPQwnW
TLSH
7D46221627C58A98E53E83B84878898267F0B95BFB15CB1D79C953DC0E027C6A717B33

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Yc7xqrQ6R9iek.g.resources
Yc7xqrQ6R9iek.Resources.resources
f23e608e4821d5.Resources.resources
908461f70
[NBF]root.Data
908461f71
[NBF]root.Data
908461f710
[NBF]root.Data
908461f7100
[NBF]root.Data
908461f7101
[NBF]root.Data
908461f7102
[NBF]root.Data
908461f7103
[NBF]root.Data
908461f7104
[NBF]root.Data
908461f7105
[NBF]root.Data
908461f7106
[NBF]root.Data
908461f7107
[NBF]root.Data
908461f7108
[NBF]root.Data
908461f7109
[NBF]root.Data
908461f711
[NBF]root.Data
908461f7110
[NBF]root.Data
908461f7111
[NBF]root.Data
908461f7112
[NBF]root.Data
908461f7113
[NBF]root.Data
908461f7114
[NBF]root.Data
908461f7115
[NBF]root.Data
908461f7116
[NBF]root.Data
908461f7117
[NBF]root.Data
908461f7118
[NBF]root.Data
908461f7119
[NBF]root.Data
908461f712
[NBF]root.Data
908461f7120
[NBF]root.Data
908461f7121
[NBF]root.Data
908461f7122
[NBF]root.Data
908461f7123
[NBF]root.Data
908461f7124
[NBF]root.Data
908461f7125
[NBF]root.Data
908461f7126
[NBF]root.Data
908461f7127
[NBF]root.Data
908461f7128
[NBF]root.Data
908461f7129
[NBF]root.Data
908461f713
[NBF]root.Data
908461f7130
[NBF]root.Data
908461f7131
[NBF]root.Data
908461f7132
[NBF]root.Data
908461f7133
[NBF]root.Data
908461f7134
[NBF]root.Data
908461f7135
[NBF]root.Data
908461f7136
[NBF]root.Data
908461f7137
[NBF]root.Data
908461f7138
[NBF]root.Data
908461f7139
[NBF]root.Data
908461f714
[NBF]root.Data
908461f7140
[NBF]root.Data
908461f7141
[NBF]root.Data
908461f7142
[NBF]root.Data
908461f7143
[NBF]root.Data
908461f7144
[NBF]root.Data
908461f7145
[NBF]root.Data
908461f7146
[NBF]root.Data
908461f7147
[NBF]root.Data
908461f7148
[NBF]root.Data
908461f7149
[NBF]root.Data
908461f715
[NBF]root.Data
908461f7150
[NBF]root.Data
908461f7151
[NBF]root.Data
908461f7152
[NBF]root.Data
908461f7153
[NBF]root.Data
908461f7154
[NBF]root.Data
908461f7155
[NBF]root.Data
908461f7156
[NBF]root.Data
908461f7157
[NBF]root.Data
908461f7158
[NBF]root.Data
908461f7159
[NBF]root.Data
908461f716
[NBF]root.Data
908461f7160
[NBF]root.Data
908461f7161
[NBF]root.Data
908461f7162
[NBF]root.Data
908461f7163
[NBF]root.Data
908461f7164
[NBF]root.Data
908461f7165
[NBF]root.Data
908461f7166
[NBF]root.Data
908461f7167
[NBF]root.Data
908461f7168
[NBF]root.Data
908461f7169
[NBF]root.Data
908461f717
[NBF]root.Data
908461f7170
[NBF]root.Data
908461f7171
[NBF]root.Data
908461f7172
[NBF]root.Data
908461f7173
[NBF]root.Data
908461f7174
[NBF]root.Data
908461f7175
[NBF]root.Data
908461f7176
[NBF]root.Data
908461f7177
[NBF]root.Data
908461f7178
[NBF]root.Data
908461f7179
[NBF]root.Data
908461f718
[NBF]root.Data
908461f7180
[NBF]root.Data
908461f7181
[NBF]root.Data
908461f7182
[NBF]root.Data
908461f7183
[NBF]root.Data
908461f7184
[NBF]root.Data
908461f7185
[NBF]root.Data
908461f7186
[NBF]root.Data
908461f7187
[NBF]root.Data
908461f7188
[NBF]root.Data
908461f7189
[NBF]root.Data
908461f719
[NBF]root.Data
908461f7190
[NBF]root.Data
908461f7191
[NBF]root.Data
908461f7192
[NBF]root.Data
908461f7193
[NBF]root.Data
908461f7194
[NBF]root.Data
908461f7195
[NBF]root.Data
908461f7196
[NBF]root.Data
908461f7197
[NBF]root.Data
908461f7198
[NBF]root.Data
908461f7199
[NBF]root.Data
908461f72
[NBF]root.Data
908461f720
[NBF]root.Data
908461f7200
[NBF]root.Data
908461f7201
[NBF]root.Data
908461f7202
[NBF]root.Data
908461f7203
[NBF]root.Data
908461f7204
[NBF]root.Data
908461f7205
[NBF]root.Data
908461f7206
[NBF]root.Data
908461f7207
[NBF]root.Data
908461f7208
[NBF]root.Data
908461f7209
[NBF]root.Data
908461f721
[NBF]root.Data
908461f7210
[NBF]root.Data
908461f7211
[NBF]root.Data
908461f7212
[NBF]root.Data
908461f7213
[NBF]root.Data
908461f7214
[NBF]root.Data
908461f7215
[NBF]root.Data
908461f7216
[NBF]root.Data
908461f7217
[NBF]root.Data
908461f7218
[NBF]root.Data
908461f7219
[NBF]root.Data
908461f722
[NBF]root.Data
908461f7220
[NBF]root.Data
908461f7221
[NBF]root.Data
908461f7222
[NBF]root.Data
908461f7223
[NBF]root.Data
908461f7224
[NBF]root.Data
908461f7225
[NBF]root.Data
908461f7226
[NBF]root.Data
908461f7227
[NBF]root.Data
908461f7228
[NBF]root.Data
908461f7229
[NBF]root.Data
908461f723
[NBF]root.Data
908461f7230
[NBF]root.Data
908461f7231
[NBF]root.Data
908461f7232
[NBF]root.Data
908461f7233
[NBF]root.Data
908461f7234
[NBF]root.Data
908461f7235
[NBF]root.Data
908461f7236
[NBF]root.Data
908461f7237
[NBF]root.Data
908461f7238
[NBF]root.Data
908461f7239
[NBF]root.Data
908461f724
[NBF]root.Data
908461f7240
[NBF]root.Data
908461f7241
[NBF]root.Data
908461f7242
[NBF]root.Data
908461f7243
[NBF]root.Data
908461f7244
[NBF]root.Data
908461f7245
[NBF]root.Data
908461f7246
[NBF]root.Data
908461f7247
[NBF]root.Data
908461f7248
[NBF]root.Data
908461f7249
[NBF]root.Data
908461f725
[NBF]root.Data
908461f7250
[NBF]root.Data
908461f7251
[NBF]root.Data
908461f7252
[NBF]root.Data
908461f7253
[NBF]root.Data
908461f7254
[NBF]root.Data
908461f7255
[NBF]root.Data
908461f7256
[NBF]root.Data
908461f7257
[NBF]root.Data
908461f7258
[NBF]root.Data
908461f7259
[NBF]root.Data
908461f726
[NBF]root.Data
908461f7260
[NBF]root.Data
908461f7261
[NBF]root.Data
908461f7262
[NBF]root.Data
908461f7263
[NBF]root.Data
908461f7264
[NBF]root.Data
908461f7265
[NBF]root.Data
908461f7266
[NBF]root.Data
908461f7267
[NBF]root.Data
908461f7268
[NBF]root.Data
908461f7269
[NBF]root.Data
908461f727
[NBF]root.Data
908461f7270
[NBF]root.Data
908461f7271
[NBF]root.Data
908461f7272
[NBF]root.Data
908461f7273
[NBF]root.Data
908461f7274
[NBF]root.Data
908461f7275
[NBF]root.Data
908461f7276
[NBF]root.Data
908461f7277
[NBF]root.Data
908461f7278
[NBF]root.Data
908461f7279
[NBF]root.Data
908461f728
[NBF]root.Data
908461f7280
[NBF]root.Data
908461f7281
[NBF]root.Data
908461f7282
[NBF]root.Data
908461f729
[NBF]root.Data
908461f73
[NBF]root.Data
908461f730
[NBF]root.Data
908461f731
[NBF]root.Data
908461f732
[NBF]root.Data
908461f733
[NBF]root.Data
908461f734
[NBF]root.Data
908461f735
[NBF]root.Data
908461f736
[NBF]root.Data
908461f737
[NBF]root.Data
908461f738
[NBF]root.Data
908461f739
[NBF]root.Data
908461f74
[NBF]root.Data
908461f740
[NBF]root.Data
908461f741
[NBF]root.Data
908461f742
[NBF]root.Data
908461f743
[NBF]root.Data
908461f744
[NBF]root.Data
908461f745
[NBF]root.Data
908461f746
[NBF]root.Data
908461f747
[NBF]root.Data
908461f748
[NBF]root.Data
908461f749
[NBF]root.Data
908461f75
[NBF]root.Data
908461f750
[NBF]root.Data
908461f751
[NBF]root.Data
908461f752
[NBF]root.Data
908461f753
[NBF]root.Data
908461f754
[NBF]root.Data
908461f755
[NBF]root.Data
908461f756
[NBF]root.Data
908461f757
[NBF]root.Data
908461f758
[NBF]root.Data
908461f759
[NBF]root.Data
908461f76
[NBF]root.Data
908461f760
[NBF]root.Data
908461f761
[NBF]root.Data
908461f762
[NBF]root.Data
908461f763
[NBF]root.Data
908461f764
[NBF]root.Data
908461f765
[NBF]root.Data
908461f766
[NBF]root.Data
908461f767
[NBF]root.Data
908461f768
[NBF]root.Data
908461f769
[NBF]root.Data
908461f77
[NBF]root.Data
908461f770
[NBF]root.Data
908461f771
[NBF]root.Data
908461f772
[NBF]root.Data
908461f773
[NBF]root.Data
908461f774
[NBF]root.Data
908461f775
[NBF]root.Data
908461f776
[NBF]root.Data
908461f777
[NBF]root.Data
908461f778
[NBF]root.Data
908461f779
[NBF]root.Data
908461f78
[NBF]root.Data
908461f780
[NBF]root.Data
908461f781
[NBF]root.Data
908461f782
[NBF]root.Data
908461f783
[NBF]root.Data
908461f784
[NBF]root.Data
908461f785
[NBF]root.Data
908461f786
[NBF]root.Data
908461f787
[NBF]root.Data
908461f788
[NBF]root.Data
908461f789
[NBF]root.Data
908461f79
[NBF]root.Data
908461f790
[NBF]root.Data
908461f791
[NBF]root.Data
908461f792
[NBF]root.Data
908461f793
[NBF]root.Data
908461f794
[NBF]root.Data
908461f795
[NBF]root.Data
908461f796
[NBF]root.Data
908461f797
[NBF]root.Data
908461f798
[NBF]root.Data
908461f799
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Yc7xqrQ6R9iek

Full Name

Yc7xqrQ6R9iek

EntryPoint

System.Void Yc7xqrQ6R9iek.7okPnxR85zgQF/Wbq53MobSi.Rpo4tW6se5iK::3BawDj2()

Scope Name

Yc7xqrQ6R9iek

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yc7xqrQ6R9iek

Assembly Version

1.22.8.18

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void Yc7xqrQ6R9iek.7okPnxR85zgQF/Wbq53MobSi.Rpo4tW6se5iK::3BawDj2()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void Yc7xqrQ6R9iek.9cmFteB5D1nki::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

Yc7xqrQ6R9iek

Full Name

Yc7xqrQ6R9iek

EntryPoint

System.Void Yc7xqrQ6R9iek.7okPnxR85zgQF/Wbq53MobSi.Rpo4tW6se5iK::3BawDj2()

Scope Name

Yc7xqrQ6R9iek

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yc7xqrQ6R9iek

Assembly Version

1.22.8.18

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void Yc7xqrQ6R9iek.7okPnxR85zgQF/Wbq53MobSi.Rpo4tW6se5iK::3BawDj2()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void Yc7xqrQ6R9iek.9cmFteB5D1nki::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

6674ee0be1fe99e615c84ed2a1bb72b0 (5.59 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙