Suspicious
Suspect

76289c0c28a13284324b40cf5c202963

PE Executable
|
MD5: 76289c0c28a13284324b40cf5c202963
|
Size: 2.25 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
76289c0c28a13284324b40cf5c202963
Sha1
8afb3a2125bc75252b8ec753de8fcc3e300d9aae
Sha256
dc139560f851883ccd1fe90bb021d5294f25bc7f04c82fdfa03555112528d7e1
Sha384
c9a9a65069e3180eb48a1f3e291ab20977323dd9b80c895d0160cdd5021ddf08056aabc8f2d2072d353e314e895049b9
Sha512
b21547509a499a25240dc93e3a9c8dddf717e3f397eeb5f7d7679e2358af569ed044c8a7cf1f82e5d33ade2ccc18ab5a4205b852150de3769027c1732e2b4efe
SSDeep
49152:pi2OYLT6IvlA3vuL6AkO19uIO8Q6w2U2P1G4rhDa3WjCVZ:3r6G+3vCXac02P1Gua3Wub
TLSH
24A53392BDF88460DB8CB577F10019DD25C6B729791EE3B335E763141EB9BE0A106CA8

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GHAT&&
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\source\repos\GHAT\GHAT\obj\Debug\GHAT.pdb

Module Name

GHAT.exe

Full Name

GHAT.exe

EntryPoint

System.Void A.cf8810019a5d531fc29035f2e396a0dfe::c307cfe9e39cf7abc7fbc0122b6d14bd8()

Scope Name

GHAT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

GHAT

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5.1

Total Strings

5

Main Method

System.Void A.cf8810019a5d531fc29035f2e396a0dfe::c307cfe9e39cf7abc7fbc0122b6d14bd8()

Main IL Instruction Count

12

Main IL

call System.Void A.c6e29bda69a7de29ae2b9312bb3e7f012::c587fa52ddeeca0f181fdfc1d37a751fa() nop <null> nop <null> call System.Void A.c609b018aa37047d6caf20f391e9c7c50::c6b32d6d92e388ce759c54f24e72538f4() nop <null> nop <null> leave.s IL_0015: ret pop <null> nop <null> nop <null> leave.s IL_0015: ret ret <null>

Module Name

GHAT.exe

Full Name

GHAT.exe

EntryPoint

System.Void A.cf8810019a5d531fc29035f2e396a0dfe::c307cfe9e39cf7abc7fbc0122b6d14bd8()

Scope Name

GHAT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

GHAT

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5.1

Total Strings

5

Main Method

System.Void A.cf8810019a5d531fc29035f2e396a0dfe::c307cfe9e39cf7abc7fbc0122b6d14bd8()

Main IL Instruction Count

12

Main IL

call System.Void A.c6e29bda69a7de29ae2b9312bb3e7f012::c587fa52ddeeca0f181fdfc1d37a751fa() nop <null> nop <null> call System.Void A.c609b018aa37047d6caf20f391e9c7c50::c6b32d6d92e388ce759c54f24e72538f4() nop <null> nop <null> leave.s IL_0015: ret pop <null> nop <null> nop <null> leave.s IL_0015: ret ret <null>

76289c0c28a13284324b40cf5c202963 (2.25 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GHAT&&
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙