Suspicious
Suspect

7a133143f56010611ad9a0e53aabe867

PE Executable
|
MD5: 7a133143f56010611ad9a0e53aabe867
|
Size: 587.78 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
7a133143f56010611ad9a0e53aabe867
Sha1
c5f70909b377e42b0d6202a803cc29cfa43bcb63
Sha256
0dd222af5bfa5496a6165b88902a3b366547ba623edbe61c75cb63aca1663851
Sha384
8eeb31e6ce59aad86cd0c5939f5df8d953b7a7644dde068e07bc8352505cd83f60492c8a917be0cd3f3543d42cbc38c0
Sha512
0731c3c0f3567c0b7443e4229d032a2ffd78be39ebaef49e35d64f0b2e410c6a806b0fb4a1b1018ccc13f15d62f6dea6420b14a7df26f5a4fd55c06acf60a093
SSDeep
12288:87hTyOTPeSLX4wWjXliEhsnS/Ex83APRyMfQRKNdqBoiV9p9p+UJ:89TyOekXbiXQ5x8wZvfQkWlV9p9p+U
TLSH
CFC4235B73BFE239C3490F76ECB0EB1C0291D3CBC416F71AB58D26462686B92AB50D51

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Frhahnkkmkp.Properties.Resources.resources
Hhhqwqbxzmj
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Frhahnkkmkp.exe

Full Name

Frhahnkkmkp.exe

EntryPoint

System.Void Frhahnkkmkp.Mhcqawbbxt::Main()

Scope Name

Frhahnkkmkp.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Frhahnkkmkp

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

12

Main Method

System.Void Frhahnkkmkp.Mhcqawbbxt::Main()

Main IL Instruction Count

19

Main IL

br IL_0041: newobj System.Void Frhahnkkmkp.Qgxmpr::.ctor() ret <null> nop <null> ldloc.s V_0 call System.Byte[] Frhahnkkmkp.Properties.Riqxsnuwvxo::get_Hhhqwqbxzmj() ldsfld System.Byte[] Frhahnkkmkp.Core.Utilities.GlobalArgument::_ArgumentViewers ldsfld System.Byte[] Frhahnkkmkp.Core.Utilities.GlobalArgument::efficientArgumentItems ldstr sCbrs5oM8R7S718cXH.EBgNkST4BbSSUjA01N ldstr iEq7iO8U1 callvirt System.Void Frhahnkkmkp.Qgxmpr::Whputovfuao(System.Byte[],System.Byte[],System.Byte[],System.String,System.String) br IL_002C: leave IL_0005 leave IL_0005: ret pop <null> br IL_0037: leave IL_0005 leave IL_0005: ret br IL_0005: ret newobj System.Void Frhahnkkmkp.Qgxmpr::.ctor() stloc.s V_0 br IL_0006: nop

Module Name

Frhahnkkmkp.exe

Full Name

Frhahnkkmkp.exe

EntryPoint

System.Void Frhahnkkmkp.Mhcqawbbxt::Main()

Scope Name

Frhahnkkmkp.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Frhahnkkmkp

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

12

Main Method

System.Void Frhahnkkmkp.Mhcqawbbxt::Main()

Main IL Instruction Count

19

Main IL

br IL_0041: newobj System.Void Frhahnkkmkp.Qgxmpr::.ctor() ret <null> nop <null> ldloc.s V_0 call System.Byte[] Frhahnkkmkp.Properties.Riqxsnuwvxo::get_Hhhqwqbxzmj() ldsfld System.Byte[] Frhahnkkmkp.Core.Utilities.GlobalArgument::_ArgumentViewers ldsfld System.Byte[] Frhahnkkmkp.Core.Utilities.GlobalArgument::efficientArgumentItems ldstr sCbrs5oM8R7S718cXH.EBgNkST4BbSSUjA01N ldstr iEq7iO8U1 callvirt System.Void Frhahnkkmkp.Qgxmpr::Whputovfuao(System.Byte[],System.Byte[],System.Byte[],System.String,System.String) br IL_002C: leave IL_0005 leave IL_0005: ret pop <null> br IL_0037: leave IL_0005 leave IL_0005: ret br IL_0005: ret newobj System.Void Frhahnkkmkp.Qgxmpr::.ctor() stloc.s V_0 br IL_0006: nop

7a133143f56010611ad9a0e53aabe867 (587.78 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙