Suspicious
Suspect

76624328d13bd5b595511a0e6f4a329c

PE Executable
|
MD5: 76624328d13bd5b595511a0e6f4a329c
|
Size: 839.68 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
76624328d13bd5b595511a0e6f4a329c
Sha1
e7ff1a69fd417c0815603a9ebe420eb930e60e87
Sha256
9684f80b2fb8393bffc51322f505080a4d29054d7821d81741f6662a7d4107e6
Sha384
b0f5b96b3aa190a1975fcc042526433aadbf3c72c0374c90c3001030dbc70f2afe98004598917332228fb152855e68ba
Sha512
4582fb71efa6331469dd9981e75e47918e54fe7d2bfbb36a3e6578e1c661d711dc1f5be42f1f226d900afe6384f771a6a6984b7a91f1f0b035470204226fb6ea
SSDeep
24576:fofN3KRKjAbGTh5ofa+NFIMV3OiUMwmTYzF:feKQl5ofa658iZCF
TLSH
9B05DFAD3354B98FC463CE728964DD70A6247DA6971BC20390E75DAFBC0D687DE102E2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
BjNC
[NBF]root.Data
[NBF]root.Data-preview.png
Teacher
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

PSta.exe

Full Name

PSta.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

PSta.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

PSta

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

25

Main IL

nop <null> ldc.i4 -1504403919 ldc.i4 -2146100819 xor <null> dup <null> stloc.0 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0038: ldc.i4.0 call System.Void ClipboardAnalyzer.Program::‭‬‮‬‏‮‍‌‏‏‍‮‭‏‫‎‪‮‌‫‎‫‭‮() nop <null> ldloc.0 <null> ldc.i4 1679395433 mul <null> ldc.i4 -1314408229 xor <null> br.s IL_0006: ldc.i4 -2146100819 ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‌‬‍‎‏‌‌​‏‍‭‮‬‫‬‮‍‬‎‬‏‍‎‮‎​‎​‫‮(System.Boolean) nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‏‮‪‭‎‌‍‍​‏‌‮‏‏‮(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

PSta.exe

Full Name

PSta.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

PSta.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

PSta

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

25

Main IL

nop <null> ldc.i4 -1504403919 ldc.i4 -2146100819 xor <null> dup <null> stloc.0 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0038: ldc.i4.0 call System.Void ClipboardAnalyzer.Program::‭‬‮‬‏‮‍‌‏‏‍‮‭‏‫‎‪‮‌‫‎‫‭‮() nop <null> ldloc.0 <null> ldc.i4 1679395433 mul <null> ldc.i4 -1314408229 xor <null> br.s IL_0006: ldc.i4 -2146100819 ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‌‬‍‎‏‌‌​‏‍‭‮‬‫‬‮‍‬‎‬‏‍‎‮‎​‎​‫‮(System.Boolean) nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‏‮‪‭‎‌‍‍​‏‌‮‏‏‮(System.Windows.Forms.Form) nop <null> ret <null>

76624328d13bd5b595511a0e6f4a329c (839.68 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
BjNC
[NBF]root.Data
[NBF]root.Data-preview.png
Teacher
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙