Suspicious
Suspect

9323f7a482830e191c832f174865dfbf

PE Executable
|
MD5: 9323f7a482830e191c832f174865dfbf
|
Size: 827.4 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
9323f7a482830e191c832f174865dfbf
Sha1
cfd47e1aebcf6beea8c4fae741543f1d3ea6ccc1
Sha256
0015911fab4e4cedd52c9fca15fc8556407bb92b23673dd4463e95f766c7349a
Sha384
64a1e1db8a320b86d8a59a6bab3e742b568dd4a294449a08d596050c7fb4652247cd5a181bea379d726168cc6eaebf2a
Sha512
f181f7e8b266a09c7cf1388e568536e6b09a14650f55a6cb62a0eca79de4e20e411d5655869383f417cb326f7d117eabbe15a32486c0f9f421e26e8557e4a037
SSDeep
12288:y9FafINR+V236+49+fb32Vb4a30seJKxMJSkR:y9EfINj699+TmV4akNJxX
TLSH
E6054CD1B150C89AED6B09F1AD2BE5302497BE9D94A4810C56DDBF1B76F3342209FE0E

PeID

Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
SC
[NBF]root.Data
zLtJ
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0xC6A00 size 13832 bytes

Info

PDB Path: GAFn.pdb

Module Name

GAFn.exe

Full Name

GAFn.exe

EntryPoint

System.Void CoinFlipSimulator.Program::Main()

Scope Name

GAFn.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

GAFn

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

128

Main Method

System.Void CoinFlipSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

GAFn.exe

Full Name

GAFn.exe

EntryPoint

System.Void CoinFlipSimulator.Program::Main()

Scope Name

GAFn.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

GAFn

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

128

Main Method

System.Void CoinFlipSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

9323f7a482830e191c832f174865dfbf (827.4 KB)
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
SC
[NBF]root.Data
zLtJ
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙