Suspicious
Suspect

7cb79778425a1e6226b510f6cd196258

PE Executable
MD5: 7cb79778425a1e6226b510f6cd196258
Size: 6.86 MB
application/x-dosexec
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
7cb79778425a1e6226b510f6cd196258
Sha1
d14dc8cb797e8662ae5f3614392a0391cdb7571e
Sha256
65fb4dbc4139471d0b512e72b3d96e18aa840cde86dc4ff3a0abf9aa477ed8cb
Sha384
672c7079c8d5d5f9e5c1106acee636eb1ace993a2f7ffc435fa8266e733c7d2d28bcc46244e30831a210bc749da4c697
Sha512
081bf2c27695bd8cff1c86dc84fb25806cae8088c238697051623316d2f4cb94e6e317422eb9899380feed1442fb27c892f58a1f342a6f9032084788226a45ea
SSDeep
49152:eb40Sp83rdQs/fPFrS5ZoDJ99FmR0JGuuVfeE03qEeFCmJiPc1Y2okWWJ3MECLRv:eBqcuZotiVGEJVzYL7ZDbQn9C
TLSH
6E668C0AA7D40AE4D167DE34CA628332EE717C425633C34F1695E64A1F336A18F6BB35

PeID

MASM/TASM - sig4 (h)
Microsoft Visual C++ 8.0 (DLL)
Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\User\Desktop\k\stub\bin\Release\net10.0-windows\win-x64\native\windowsdesktop-runtime-9.0.15-win-x64.pdb

Artefacts
Name
Value
URLs in VB Code - #1

https://github.com/dotnet/dotnet

URLs in VB Code - #2

https://github.com/dotnet/runtime

URLs in VB Code - #3

https://aka.ms/dotnet-warnings/

URLs in VB Code - #4

https://aka.ms/binaryformatter

URLs in VB Code - #5

https://aka.ms/serializationformat-binary-obsolete

7cb79778425a1e6226b510f6cd196258 (6.86 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙