Suspicious
Suspect

93f735e46813ec10eb69df3b2314b561

PE Executable
|
MD5: 93f735e46813ec10eb69df3b2314b561
|
Size: 719.36 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
93f735e46813ec10eb69df3b2314b561
Sha1
85bdec3711afd6bf0bbac5a9cc74d681cc39505b
Sha256
c5632d6ab65d267d13aacabbb8c23b65d1745a9aebbc64955a157efd1e2ea352
Sha384
e75efc12d2f6397e6194d0ba637c9c0054aa99a6395f312c2a0085eee1ca7da36fca7ddd99f83e5f847e7cac5fb9fe48
Sha512
495446c2faf978a98103e5121612e6374d60e78f28e6c043cea610c9cdb1348df149038e242cba3bade806dc734f9f3c3a81469d28c0f80f306de9297af76828
SSDeep
12288:4IEU01clhYErU5aB/raxosHcvQ7WO7Tu9km7UHBznB2bmCehz6pPI6o4Tl:4UlhYk8a9rOrHcvQt7Tu9kmQBkbgh+BT
TLSH
5AE4225DBB21A510E52C9BBAC257208405F1C07BF491FB6A15C59CFA4E36E4CCA1BF8B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

gdFg.exe

Full Name

gdFg.exe

EntryPoint

System.Void HabitTracker.Program::Main()

Scope Name

gdFg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gdFg

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void HabitTracker.Program::Main()

Main IL Instruction Count

33

Main IL

ldc.i4.0 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void HabitTracker.Habit::Ⴄ() ldc.i4 617 ldc.i4 542 call System.Void HabitTracker.MainForm::Ⴍ(System.Int16,System.Int16) ldc.i4.0 <null> ldc.i4.s 105 ldc.i4.s 96 call System.Void HabitTracker.Properties.Resources::Ⴗ(System.Boolean,System.Int32,System.Char) ldc.i4.1 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void HabitTracker.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void HabitTracker.Program::Main() pop <null> ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 89 ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 89 ldelem.u2 <null> ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 35 ldelem.u2 <null> sub <null> ldc.i4.s 57 and <null> stelem.i2 <null> ret <null>

Module Name

gdFg.exe

Full Name

gdFg.exe

EntryPoint

System.Void HabitTracker.Program::Main()

Scope Name

gdFg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gdFg

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void HabitTracker.Program::Main()

Main IL Instruction Count

33

Main IL

ldc.i4.0 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void HabitTracker.Habit::Ⴄ() ldc.i4 617 ldc.i4 542 call System.Void HabitTracker.MainForm::Ⴍ(System.Int16,System.Int16) ldc.i4.0 <null> ldc.i4.s 105 ldc.i4.s 96 call System.Void HabitTracker.Properties.Resources::Ⴗ(System.Boolean,System.Int32,System.Char) ldc.i4.1 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void HabitTracker.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void HabitTracker.Program::Main() pop <null> ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 89 ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 89 ldelem.u2 <null> ldsfld System.Char[] <PrivateImplementationDetails>::Ⴗ ldc.i4.s 35 ldelem.u2 <null> sub <null> ldc.i4.s 57 and <null> stelem.i2 <null> ret <null>

93f735e46813ec10eb69df3b2314b561 (719.36 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙