Suspicious
Suspect

6fe888614a82f786a5c65493b2c74070

PE Executable
|
MD5: 6fe888614a82f786a5c65493b2c74070
|
Size: 1.55 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
6fe888614a82f786a5c65493b2c74070
Sha1
d40fef1d7ced5058221bc7a4a0b9be6d8c155b6b
Sha256
b7e4109f5c69a0a60796626e91ce4dae79038d3e193eed55f2da46f5217f1318
Sha384
b8c5d167e7999c9b6f9e02de3981048b58bd31383cebf1382ebe139bd5862ba782a963e382315e4f7bc9f8f09d631750
Sha512
c0ed625da9cc2c9a0a28e50af553a1e549a9620e4e95cc6abbde206deedca2aa8fa12eafdde30e5e5180ed365bf7c705fa64d4455d5cff6d7c36fa030ab0be51
SSDeep
24576:ONy1/2Mj/szy0gdxhzMLYv1ibPV4HWEgt1rGuxlu7ElgklRPEf:xd2lm0g/dkRdXBu76ggEf
TLSH
2775F1B1B2F18859D48966714926D83421E71DBCECA1D30ED4DA7DAB79B3FC3088294F

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Zapsinaya_knizka_new.Form01.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Form1.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Properties.Resources.resources
de
[NBF]root.Data
lHOX
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ?

Module Name

gayD.exe

Full Name

gayD.exe

EntryPoint

System.Void Zapsinaya_knizka_new.Program::Main()

Scope Name

gayD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gayD

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

217

Main Method

System.Void Zapsinaya_knizka_new.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Zapsinaya_knizka_new.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

gayD.exe

Full Name

gayD.exe

EntryPoint

System.Void Zapsinaya_knizka_new.Program::Main()

Scope Name

gayD.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gayD

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

217

Main Method

System.Void Zapsinaya_knizka_new.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Zapsinaya_knizka_new.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

6fe888614a82f786a5c65493b2c74070 (1.55 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Zapsinaya_knizka_new.Form01.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Form1.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Properties.Resources.resources
de
[NBF]root.Data
lHOX
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙