Suspicious
Suspect

6d652a758df98f46450389db5feadaa8

PE Executable
|
MD5: 6d652a758df98f46450389db5feadaa8
|
Size: 720.9 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
6d652a758df98f46450389db5feadaa8
Sha1
6fc074aca06248c7664a5dac48d79914e063f357
Sha256
9d6279109af5c9b69c2c09e5b27fb1d850508496dfbb9d0da623b3b4dc757468
Sha384
faf3625e5834cdd16bf07f355f3ef9539555e4daf3d53001a39cde743694e762f32352cad29bc042605a431c112fef46
Sha512
02e892e3acb5079041cf38a89cd3839c80dc3049089fbbab936b1a2fa49eed060e56f9d6bab1b0a933bc85a993fee6edaf04b851f500cdf20348a61cfeceb9c4
SSDeep
12288:piwSnA9JKNZ0xmGUiTQmno0nkoPf5uItZgFHVGXcCAe4M0Caqz8YCWGQYyHVga1l:pSnA9JKN6AGUtCn7PRptqFHQX9KM0PDl
TLSH
51E41225631AED07E4A703754CE1E7F4275CADDDA911C30F8BDA6CE73C2AB04389529A
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
gap
[NBF]root.Data
tBLa
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: THma.pdb

Module Name

THma.exe

Full Name

THma.exe

EntryPoint

System.Void NumberGuess.Program::Main()

Scope Name

THma.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

THma

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

102

Main Method

System.Void NumberGuess.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NumberGuess.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

6d652a758df98f46450389db5feadaa8 (720.9 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
gap
[NBF]root.Data
tBLa
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙