Suspicious
Suspect

78ba1ff15b8658b703fdbdc13764cc4b

PE Executable
|
MD5: 78ba1ff15b8658b703fdbdc13764cc4b
|
Size: 1.31 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
78ba1ff15b8658b703fdbdc13764cc4b
Sha1
cb4d7dad5a39f262ffffe1a835fad34aeec63d7c
Sha256
7788888fd7848d1a7242ffe9ee59c95147d1427e69c099e08cffae2fa1c8835a
Sha384
d9f21bd02aa42f6eb1fbc5f0c98de06fc59007f427e5848b1e4346ac2d8b3621096c6b501e069c153d72b106531fdb5e
Sha512
a4e6b035b2fe2f701766503617d05eae966548e01af4170a2056fea1e061e242cf8a2b602ce697da23675af96405e286868b1c68dbeff64de04bf8a200ae97a8
SSDeep
24576:fHAN4wOz68l+x6SiA07xpp9b6EtIkgl0g2XDpxK24BUdq5+NWKmZmFcc:fHAN4wOu8l+xFiASpp9+EmkglZ2XdxKk
TLSH
B05523421A19D642D56B1FB00E3BC07423B41D85A936D31FDAC93E9B78BFE7449342AB

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ExtensionSearch.MainForm.resources
ExtensionSearch.Properties.Resources.resources
Mars
[NBF]root.Data
rrvf
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: Ltjl.pdb

Module Name

Ltjl.exe

Full Name

Ltjl.exe

EntryPoint

System.Void ExtensionSearch.Program::Main()

Scope Name

Ltjl.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ltjl

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void ExtensionSearch.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ExtensionSearch.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

Ltjl.exe

Full Name

Ltjl.exe

EntryPoint

System.Void ExtensionSearch.Program::Main()

Scope Name

Ltjl.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ltjl

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

96

Main Method

System.Void ExtensionSearch.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ExtensionSearch.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

78ba1ff15b8658b703fdbdc13764cc4b (1.31 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙