Suspicious
Suspect

6fb61b541b2245afb18814909c99a313

PE Executable
|
MD5: 6fb61b541b2245afb18814909c99a313
|
Size: 750.08 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
6fb61b541b2245afb18814909c99a313
Sha1
c84865aea1b5fd8b7c2b506ba317928af6bb57e1
Sha256
617b4ff46fd1b162ad5e7b780297ce197fdcf199449c5afda6b389d0c2755073
Sha384
17fca72409e0bf7c7f76fbf0af0e0d9aeaecfbe841abad9e6bb22365e92dae9263228e6616317e408f6cc3969f7015e6
Sha512
06b194c8ae11019d4cf29514289bedd0ffb970cf1f86b7d9fb5f102b1229406cd50e63e36f1fd1f027a154235ea941609a2c487962b8419f950d9d24d477f6f3
SSDeep
12288:VKzjuyojGYZJc+0fQj7P1MrgqN/0XZ/ez2G7BBGXytENR6/Zv8Xfz:Ez4jGYI/fQMrlNQrMsNwB8
TLSH
82F4029C6A8EE913CC544BB545E3E37541F89FC8F812D35BCAD97CEB3C6E2952801292
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
serverapp.Form1.resources
$this.Icon
[NBF]root.IconData
jj
[NBF]root.Data
serverapp.Properties.Resources.resources
QOOf
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Module Name

KOBf.exe

Full Name

KOBf.exe

EntryPoint

System.Void serverapp.Program::Main(System.String[])

Scope Name

KOBf.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

KOBf

Assembly Version

7.8.6.7

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

99

Main Method

System.Void serverapp.Program::Main(System.String[])

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void serverapp.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Artefacts
Name
Value
PDB Path

C:\Users\Administrator\Desktop\Client\Temp\OmutqIGWXY\src\obj\Debug\KOBf.pdb

Embedded Resources

2

Suspicious Type Names (1-2 chars)

0

6fb61b541b2245afb18814909c99a313 (750.08 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙