Suspicious
Suspect

825c7bb9565290a94026b5a8fadb5109

PE Executable
|
MD5: 825c7bb9565290a94026b5a8fadb5109
|
Size: 777.22 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
825c7bb9565290a94026b5a8fadb5109
Sha1
95e3a08b6252d05a8fe693a78ff1ab59f4059c91
Sha256
351184a95c114d89dcc8e2a2d1468b02b79a8d97a7ef12c98c74a577bab99664
Sha384
f2dd5785e2aa6afc7c8ca434a669e901eeea2080329556e6af46e8ec874bde6b7d0d44e146d213d314f65e183ba1562e
Sha512
1f61dfbf3138ff0799167c5b23212434faa2a511294c71553c807437999235efa1779b10e7cebcf9ab088bdcbbf40ba1218c69aec6c17167ec24a8781bfbb649
SSDeep
12288:VY0OTMfwR+42BHI+OCd5KF7mmuuYQ+82Sxb7P5hZetzIBX:V5fSilOCd5KVmZSdj5b/
TLSH
1AF41294262AEB02DA61ABF85571F1740BB83E9AF852D31A4FC47DEFB876F400C14653

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
Tiib
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: jrHU.pdb

Module Name

jrHU.exe

Full Name

jrHU.exe

EntryPoint

System.Void DiceSimulator.Program::Main()

Scope Name

jrHU.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

jrHU

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

235

Main Method

System.Void DiceSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DiceSimulator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

jrHU.exe

Full Name

jrHU.exe

EntryPoint

System.Void DiceSimulator.Program::Main()

Scope Name

jrHU.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

jrHU

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

235

Main Method

System.Void DiceSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DiceSimulator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

825c7bb9565290a94026b5a8fadb5109 (777.22 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙