Suspicious
Suspect

963bc16dc6f4b1372c6cc999cd434d2b

PE Executable
|
MD5: 963bc16dc6f4b1372c6cc999cd434d2b
|
Size: 1.51 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
963bc16dc6f4b1372c6cc999cd434d2b
Sha1
7c99842b77533063b7fe57f787849e84084566fe
Sha256
188b761d7dcaa76f11517e1f1675487d6127d0d942b20a56a5ea4127395c571b
Sha384
e859c2cca1463a86028cafeb05910dbdb2d4b2abaf0189b8ecfd5cf7713365e8ef61359e3f825a06861ec7c04d936fbf
Sha512
ecede3b141160860d6639aca7c9c7608029b82315f57e8ca7ec876e5eea4052f965cb6c7bd270c3a174e9e386aee125a0e7f67aa12663b23a4fb3aaf688ab696
SSDeep
24576:sjLgPyC/bDRGAZ/xOftanz8YZJetKdgG:scDzFGcE48YZJN
TLSH
12656B9463D5BD04C53F37753768B05483F2E8DBAAA1C20F0DD565DB37B2A412F82AA2

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
kKi7r0Gs5ma.g.resources
kKi7r0Gs5ma.1b_DL9iocj3.resources
$this.Icon
[NBF]root.IconData
GridViewRelation1.ChildColumnNames
GridViewRelation3.ChildColumnNames
GridViewRelation3.ParentColumnNames
kKi7r0Gs5ma.sZp9dx2KY6zqwN.resources
kKi7r0Gs5ma.Resources.resources
93dc587fb343ab.Resources.resources
f8acdf730
[NBF]root.Data
f8acdf731
[NBF]root.Data
f8acdf7310
[NBF]root.Data
f8acdf7311
[NBF]root.Data
f8acdf7312
[NBF]root.Data
f8acdf7313
[NBF]root.Data
f8acdf7314
[NBF]root.Data
f8acdf7315
[NBF]root.Data
f8acdf7316
[NBF]root.Data
f8acdf7317
[NBF]root.Data
f8acdf7318
[NBF]root.Data
f8acdf7319
[NBF]root.Data
f8acdf732
[NBF]root.Data
f8acdf7320
[NBF]root.Data
f8acdf7321
[NBF]root.Data
f8acdf7322
[NBF]root.Data
f8acdf7323
[NBF]root.Data
f8acdf7324
[NBF]root.Data
f8acdf7325
[NBF]root.Data
f8acdf7326
[NBF]root.Data
f8acdf7327
[NBF]root.Data
f8acdf7328
[NBF]root.Data
f8acdf7329
[NBF]root.Data
f8acdf733
[NBF]root.Data
f8acdf7330
[NBF]root.Data
f8acdf7331
[NBF]root.Data
f8acdf7332
[NBF]root.Data
f8acdf7333
[NBF]root.Data
f8acdf7334
[NBF]root.Data
f8acdf7335
[NBF]root.Data
f8acdf7336
[NBF]root.Data
f8acdf7337
[NBF]root.Data
f8acdf7338
[NBF]root.Data
f8acdf7339
[NBF]root.Data
f8acdf734
[NBF]root.Data
f8acdf7340
[NBF]root.Data
f8acdf7341
[NBF]root.Data
f8acdf7342
[NBF]root.Data
f8acdf7343
[NBF]root.Data
f8acdf7344
[NBF]root.Data
f8acdf7345
[NBF]root.Data
f8acdf7346
[NBF]root.Data
f8acdf7347
[NBF]root.Data
f8acdf7348
[NBF]root.Data
f8acdf7349
[NBF]root.Data
f8acdf735
[NBF]root.Data
f8acdf7350
[NBF]root.Data
f8acdf736
[NBF]root.Data
f8acdf737
[NBF]root.Data
f8acdf738
[NBF]root.Data
f8acdf739
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

kKi7r0Gs5ma

Full Name

kKi7r0Gs5ma

EntryPoint

System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::0GndW()

Scope Name

kKi7r0Gs5ma

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

kKi7r0Gs5ma

Assembly Version

2.14.19.228

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

9043

Main Method

System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::0GndW()

Main IL Instruction Count

46

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> ldloc.0 <null> ldc.i4.0 <null> callvirt System.Void System.Windows.Forms.Form::set_FormBorderStyle(System.Windows.Forms.FormBorderStyle) nop <null> ldloc.0 <null> ldc.i4.1 <null> callvirt System.Void System.Windows.Forms.Form::set_StartPosition(System.Windows.Forms.FormStartPosition) nop <null> ldloc.0 <null> ldc.i4.1 <null> ldc.i4.1 <null> newobj System.Void System.Drawing.Size::.ctor(System.Int32,System.Int32) callvirt System.Void System.Windows.Forms.Form::set_Size(System.Drawing.Size) nop <null> ldloc.0 <null> ldc.r8 0 callvirt System.Void System.Windows.Forms.Form::set_Opacity(System.Double) nop <null> ldloc.0 <null> ldc.i4.0 <null> callvirt System.Void System.Windows.Forms.Form::set_ShowInTaskbar(System.Boolean) nop <null> call System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::X_y3xk1() nop <null> ldloc.0 <null> callvirt System.Void System.Windows.Forms.Form::Close() nop <null> ldloc.0 <null> callvirt System.Void System.ComponentModel.Component::Dispose() nop <null> leave.s IL_006E: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_006E: nop nop <null> ret <null>

Module Name

kKi7r0Gs5ma

Full Name

kKi7r0Gs5ma

EntryPoint

System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::0GndW()

Scope Name

kKi7r0Gs5ma

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

kKi7r0Gs5ma

Assembly Version

2.14.19.228

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

9043

Main Method

System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::0GndW()

Main IL Instruction Count

46

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.0 <null> ldloc.0 <null> ldc.i4.0 <null> callvirt System.Void System.Windows.Forms.Form::set_FormBorderStyle(System.Windows.Forms.FormBorderStyle) nop <null> ldloc.0 <null> ldc.i4.1 <null> callvirt System.Void System.Windows.Forms.Form::set_StartPosition(System.Windows.Forms.FormStartPosition) nop <null> ldloc.0 <null> ldc.i4.1 <null> ldc.i4.1 <null> newobj System.Void System.Drawing.Size::.ctor(System.Int32,System.Int32) callvirt System.Void System.Windows.Forms.Form::set_Size(System.Drawing.Size) nop <null> ldloc.0 <null> ldc.r8 0 callvirt System.Void System.Windows.Forms.Form::set_Opacity(System.Double) nop <null> ldloc.0 <null> ldc.i4.0 <null> callvirt System.Void System.Windows.Forms.Form::set_ShowInTaskbar(System.Boolean) nop <null> call System.Void kKi7r0Gs5ma.sZp9dx2KY6zqwN::X_y3xk1() nop <null> ldloc.0 <null> callvirt System.Void System.Windows.Forms.Form::Close() nop <null> ldloc.0 <null> callvirt System.Void System.ComponentModel.Component::Dispose() nop <null> leave.s IL_006E: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_006E: nop nop <null> ret <null>

963bc16dc6f4b1372c6cc999cd434d2b (1.51 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
kKi7r0Gs5ma.g.resources
kKi7r0Gs5ma.1b_DL9iocj3.resources
$this.Icon
[NBF]root.IconData
GridViewRelation1.ChildColumnNames
GridViewRelation3.ChildColumnNames
GridViewRelation3.ParentColumnNames
kKi7r0Gs5ma.sZp9dx2KY6zqwN.resources
kKi7r0Gs5ma.Resources.resources
93dc587fb343ab.Resources.resources
f8acdf730
[NBF]root.Data
f8acdf731
[NBF]root.Data
f8acdf7310
[NBF]root.Data
f8acdf7311
[NBF]root.Data
f8acdf7312
[NBF]root.Data
f8acdf7313
[NBF]root.Data
f8acdf7314
[NBF]root.Data
f8acdf7315
[NBF]root.Data
f8acdf7316
[NBF]root.Data
f8acdf7317
[NBF]root.Data
f8acdf7318
[NBF]root.Data
f8acdf7319
[NBF]root.Data
f8acdf732
[NBF]root.Data
f8acdf7320
[NBF]root.Data
f8acdf7321
[NBF]root.Data
f8acdf7322
[NBF]root.Data
f8acdf7323
[NBF]root.Data
f8acdf7324
[NBF]root.Data
f8acdf7325
[NBF]root.Data
f8acdf7326
[NBF]root.Data
f8acdf7327
[NBF]root.Data
f8acdf7328
[NBF]root.Data
f8acdf7329
[NBF]root.Data
f8acdf733
[NBF]root.Data
f8acdf7330
[NBF]root.Data
f8acdf7331
[NBF]root.Data
f8acdf7332
[NBF]root.Data
f8acdf7333
[NBF]root.Data
f8acdf7334
[NBF]root.Data
f8acdf7335
[NBF]root.Data
f8acdf7336
[NBF]root.Data
f8acdf7337
[NBF]root.Data
f8acdf7338
[NBF]root.Data
f8acdf7339
[NBF]root.Data
f8acdf734
[NBF]root.Data
f8acdf7340
[NBF]root.Data
f8acdf7341
[NBF]root.Data
f8acdf7342
[NBF]root.Data
f8acdf7343
[NBF]root.Data
f8acdf7344
[NBF]root.Data
f8acdf7345
[NBF]root.Data
f8acdf7346
[NBF]root.Data
f8acdf7347
[NBF]root.Data
f8acdf7348
[NBF]root.Data
f8acdf7349
[NBF]root.Data
f8acdf735
[NBF]root.Data
f8acdf7350
[NBF]root.Data
f8acdf736
[NBF]root.Data
f8acdf737
[NBF]root.Data
f8acdf738
[NBF]root.Data
f8acdf739
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙