Suspicious
Suspect

8c9eb1aaccde7cc1a03f7d7d011cadf3

PE Executable
|
MD5: 8c9eb1aaccde7cc1a03f7d7d011cadf3
|
Size: 1.29 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
8c9eb1aaccde7cc1a03f7d7d011cadf3
Sha1
6411c03875e940e2b5dc6228f244a7bc74bb63ea
Sha256
0821ab66a63ff2fe4d38a825b7ff3c3104a89eeb88df640d3a705b95b634bf53
Sha384
acd8ab370319810fe9b86cf7a6ffe1ea98c3f924c6ec1fe935b1f1857d4d3ba2ed690b36c7cffd98d5cb0a5197e6c0be
Sha512
90f5bf1e2b7b27994c2c5ade8d3f2b6d84e6ba066cd2360649f224f2c48188ba45ccdf35eb6627da8667165d288241d0dbf03aae1d6dcb6552bff90e45b0bab5
SSDeep
24576:+guQlVict3wHj5Xeeh15vvAU+OHeZSsBryYnu0iwOdb/7v7:3uWQcyXeehvnAhOHeZSmjubXv
TLSH
C8552310224DEF02E86917F94272E379A3F55E8D5022E3168EFF5DEB759A7588C0831B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EyeReminder.Properties.Resources.resources
Clear
[NBF]root.Data
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
xgrgd
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Act

Full Name

Act

EntryPoint

System.Void IndexerGetDeleg.NetCodeGr::Main()

Scope Name

Act

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

CcSOc

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

214

Main Method

System.Void IndexerGetDeleg.NetCodeGr::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void UnverifiableCodeAttrib.CipherM::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

Act

Full Name

Act

EntryPoint

System.Void IndexerGetDeleg.NetCodeGr::Main()

Scope Name

Act

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

CcSOc

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

214

Main Method

System.Void IndexerGetDeleg.NetCodeGr::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void UnverifiableCodeAttrib.CipherM::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

8c9eb1aaccde7cc1a03f7d7d011cadf3 (1.29 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EyeReminder.Properties.Resources.resources
Clear
[NBF]root.Data
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
xgrgd
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙