Suspicious
Suspect

6935dc6198933ab606371efcb374cd9a

PE Executable
|
MD5: 6935dc6198933ab606371efcb374cd9a
|
Size: 789.5 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
6935dc6198933ab606371efcb374cd9a
Sha1
6c8a95f1d439b66e7481471ca88923e630b817db
Sha256
b49f326c7a4f5156fc6033fe83b1129ebf9679947afb36ade578a656eac96c10
Sha384
f89882ba312a347513e445ba3643918762a207d8ca11f86d63cf9f367bc11cb34d20725cd53776b7d094fb499c7fe413
Sha512
c3eb7bbb1c5aa2089eb96f21bd95abeb935136bc3aad07951dcb66f67a2d885550638f7c815e976d83ac8cf9ac2c363b1356e88b60d7647ec9de42b99161b67c
SSDeep
12288:MjyGJPztq0rlWS9aHswPxZRtyMnX72oy9tGVdxk10S0Ew4aJBRM60VfrXJKz+E:w1rlWiY+oXpyrdMEDMzMpzWd
TLSH
66F4F0D03B2A771ADEA00934E568EEB642F91D68B044BEF359DC3B57759D610AE0CF02

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FlaschenDrehen.Properties.Resources.resources
FlascheModeeee
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
cBHc
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: fAuX.pdb

Module Name

fAuX.exe

Full Name

fAuX.exe

EntryPoint

System.Void FlaschenDrehen.Program::Main()

Scope Name

fAuX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

fAuX

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

83

Main Method

System.Void FlaschenDrehen.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void FlaschenDrehen.HauptForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

fAuX.exe

Full Name

fAuX.exe

EntryPoint

System.Void FlaschenDrehen.Program::Main()

Scope Name

fAuX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

fAuX

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

83

Main Method

System.Void FlaschenDrehen.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void FlaschenDrehen.HauptForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

6935dc6198933ab606371efcb374cd9a (789.5 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FlaschenDrehen.Properties.Resources.resources
FlascheModeeee
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
cBHc
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙