Suspicious
Suspect

6da86fe3927604e619611626e33fb366

PE Executable
|
MD5: 6da86fe3927604e619611626e33fb366
|
Size: 1.75 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
6da86fe3927604e619611626e33fb366
Sha1
aa3c315da743384a77ceaa4519cfb8ad76c08653
Sha256
4978680ea558de05a0f4aafd970ffeb9123ddbe34cda433512faf68e80a6bc8a
Sha384
004f172abb1d4cf02cc67c922e9000d8d13ba90322b8e87d7b6fdc27e62f46155003a0ca97493a525973faa810d1f9bf
Sha512
8eeff5db24a48ae0ecbf22d7cc63b06a3af8c6e196b888da026e07d6bf1bf63bb832c6bf31911b5de9bce28711d031bed12ab7f020bbe93a3bc19221dccd2a41
SSDeep
12288:En/uLts2Tzg70BxGPGZD52Am2RhSHIp7bGt4w5aYETUiZhxAYMWr/b5HxiqFMEOl:Nzg0BxGPGZD52Agy1w5NCaW7ES2
TLSH
CC85F791F4A528B18146A6BDD0AE054F8F2972D7E983901FF19C6BC41F1FE81B9C7A43

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PhoneNumbers.PhoneNumberMetaData.xml
PhoneNumbers.PhoneNumberMetaDataForTesting.xml
PhoneNumbers.res.1_en
PhoneNumbers.res.31_nl
PhoneNumbers.res.34_es
PhoneNumbers.res.43_de
PhoneNumbers.res.46_sv
PhoneNumbers.res.49_de
PhoneNumbers.res.54_es
PhoneNumbers.res.55_pt
PhoneNumbers.res.56_es
PhoneNumbers.res.82_en
PhoneNumbers.res.82_ko
PhoneNumbers.res.82_zh
PhoneNumbers.res.82_zh_Hant
PhoneNumbers.res.86_zh
PhoneNumbers.res.test_1_en
PhoneNumbers.res.test_82_en
PhoneNumbers.res.test_82_ko
PhoneNumbers.res.44_en
PhoneNumbers.res.33_fr
PhoneNumbers.res.351_pt
PhoneNumbers.res.39_en
PhoneNumbers.res.39_it
PhoneNumbers.res.41_de
PhoneNumbers.res.41_en
PhoneNumbers.res.41_fr
PhoneNumbers.res.41_it
PhoneNumbers.res.7_en
PhoneNumbers.res.81_ja
PhoneNumbers.res.886_en
PhoneNumbers.res.886_zh
PhoneNumbers.res.886_zh_Hant
PhoneNumbers.res.90_en
PhoneNumbers.res.90_tr
PhoneNumbers.res.213_en
PhoneNumbers.res.216_en
PhoneNumbers.res.221_en
PhoneNumbers.res.224_en
PhoneNumbers.res.225_en
PhoneNumbers.res.226_en
PhoneNumbers.res.229_en
PhoneNumbers.res.233_en
PhoneNumbers.res.261_en
PhoneNumbers.res.264_en
PhoneNumbers.res.266_en
PhoneNumbers.res.267_en
PhoneNumbers.res.268_en
PhoneNumbers.res.354_en
PhoneNumbers.res.355_en
PhoneNumbers.res.370_en
PhoneNumbers.res.371_en
PhoneNumbers.res.372_en
PhoneNumbers.res.420_en
PhoneNumbers.res.421_en
PhoneNumbers.res.48_pl
PhoneNumbers.res.51_en
PhoneNumbers.res.84_en
PhoneNumbers.res.84_vi
PhoneNumbers.res.94_en
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Gpfknawwe.exe

Full Name

Gpfknawwe.exe

EntryPoint

System.Void PhoneNumbers.Processing.CollectorFunction::GetEfficientCollector()

Scope Name

Gpfknawwe.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Gpfknawwe

Assembly Version

1.0.1576.11619

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

555

Main Method

System.Void PhoneNumbers.Processing.CollectorFunction::GetEfficientCollector()

Main IL Instruction Count

17

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0049: nop nop <null> call System.Void PhoneNumbers.Processing.CollectorFunction::CollectInternalCollector() ldc.i4 0 ldsfld <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e} <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e}::m_f737b7b3ab1b45f9b31705daf1858533 ldfld System.Int32 <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e}::m_9ea943434c5541b998549df9a68a5c2b brfalse IL_0012: switch(IL_0049,IL_0024) pop <null> ldc.i4 0 br IL_0012: switch(IL_0049,IL_0024) nop <null> ret <null>

Module Name

Gpfknawwe.exe

Full Name

Gpfknawwe.exe

EntryPoint

System.Void PhoneNumbers.Processing.CollectorFunction::GetEfficientCollector()

Scope Name

Gpfknawwe.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Gpfknawwe

Assembly Version

1.0.1576.11619

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

555

Main Method

System.Void PhoneNumbers.Processing.CollectorFunction::GetEfficientCollector()

Main IL Instruction Count

17

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0049: nop nop <null> call System.Void PhoneNumbers.Processing.CollectorFunction::CollectInternalCollector() ldc.i4 0 ldsfld <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e} <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e}::m_f737b7b3ab1b45f9b31705daf1858533 ldfld System.Int32 <Module>{78edf9bd-2dff-4986-a25a-102401f5f97e}::m_9ea943434c5541b998549df9a68a5c2b brfalse IL_0012: switch(IL_0049,IL_0024) pop <null> ldc.i4 0 br IL_0012: switch(IL_0049,IL_0024) nop <null> ret <null>

6da86fe3927604e619611626e33fb366 (1.75 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PhoneNumbers.PhoneNumberMetaData.xml
PhoneNumbers.PhoneNumberMetaDataForTesting.xml
PhoneNumbers.res.1_en
PhoneNumbers.res.31_nl
PhoneNumbers.res.34_es
PhoneNumbers.res.43_de
PhoneNumbers.res.46_sv
PhoneNumbers.res.49_de
PhoneNumbers.res.54_es
PhoneNumbers.res.55_pt
PhoneNumbers.res.56_es
PhoneNumbers.res.82_en
PhoneNumbers.res.82_ko
PhoneNumbers.res.82_zh
PhoneNumbers.res.82_zh_Hant
PhoneNumbers.res.86_zh
PhoneNumbers.res.test_1_en
PhoneNumbers.res.test_82_en
PhoneNumbers.res.test_82_ko
PhoneNumbers.res.44_en
PhoneNumbers.res.33_fr
PhoneNumbers.res.351_pt
PhoneNumbers.res.39_en
PhoneNumbers.res.39_it
PhoneNumbers.res.41_de
PhoneNumbers.res.41_en
PhoneNumbers.res.41_fr
PhoneNumbers.res.41_it
PhoneNumbers.res.7_en
PhoneNumbers.res.81_ja
PhoneNumbers.res.886_en
PhoneNumbers.res.886_zh
PhoneNumbers.res.886_zh_Hant
PhoneNumbers.res.90_en
PhoneNumbers.res.90_tr
PhoneNumbers.res.213_en
PhoneNumbers.res.216_en
PhoneNumbers.res.221_en
PhoneNumbers.res.224_en
PhoneNumbers.res.225_en
PhoneNumbers.res.226_en
PhoneNumbers.res.229_en
PhoneNumbers.res.233_en
PhoneNumbers.res.261_en
PhoneNumbers.res.264_en
PhoneNumbers.res.266_en
PhoneNumbers.res.267_en
PhoneNumbers.res.268_en
PhoneNumbers.res.354_en
PhoneNumbers.res.355_en
PhoneNumbers.res.370_en
PhoneNumbers.res.371_en
PhoneNumbers.res.372_en
PhoneNumbers.res.420_en
PhoneNumbers.res.421_en
PhoneNumbers.res.48_pl
PhoneNumbers.res.51_en
PhoneNumbers.res.84_en
PhoneNumbers.res.84_vi
PhoneNumbers.res.94_en
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙