Suspicious
Suspect

929f8e48fe5de70663244a46a7dfa83b

PE Executable
|
MD5: 929f8e48fe5de70663244a46a7dfa83b
|
Size: 556.54 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
929f8e48fe5de70663244a46a7dfa83b
Sha1
d551a1858510396faa91782983065ed72b40db1d
Sha256
a6bc2fb206efe4340b16945ebebfeb7e30bf5d3cbad01eff2ee26120febdc627
Sha384
0d3713d745c2af7fcbf78ac7e3503fe7105586902bb479ce9e88796faef80734370eb5cef8380236dc5266db71638c14
Sha512
b7d1cd574dd68f7f3826c27bcf97b8a65e66d186285bcc1aa323caac99ed8708970812618741d303afb7ceeb8c71f703eec0b214b5d10ce35b036d24dd994484
SSDeep
12288:pLV6Btpmko/vucviyj9Gb4mPsHZwd2SggKQRrNxORd6Qc1:RApfKvucqyj9GbZP6uYS2qNxOj6d1
TLSH
2AC4125A3BB94A2FD29EC6B6710502139778C2D6A9C3F3EE0CD014BA4B577E0064B1E3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
Informations
Name
Value
Module Name

NanoCore Client.exe

Full Name

NanoCore Client.exe

EntryPoint

System.Void ClientLoaderForm::Main()

Scope Name

NanoCore Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NanoCore Client

Assembly Version

1.2.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

2

Main Method

System.Void ClientLoaderForm::Main()

Main IL Instruction Count

4

Main IL

call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==() callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

NanoCore Client.exe

Full Name

NanoCore Client.exe

EntryPoint

System.Void ClientLoaderForm::Main()

Scope Name

NanoCore Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NanoCore Client

Assembly Version

1.2.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

2

Main Method

System.Void ClientLoaderForm::Main()

Main IL Instruction Count

4

Main IL

call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==() callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

929f8e48fe5de70663244a46a7dfa83b (556.54 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙