Suspicious
Suspect

9920bcf33cfa8118680e801c248c8bb9

PE Executable
|
MD5: 9920bcf33cfa8118680e801c248c8bb9
|
Size: 749.57 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
9920bcf33cfa8118680e801c248c8bb9
Sha1
21d46ff27b0e9ac6c3910b091e6529eb335ece0c
Sha256
9c0d7aefababf691ddb1e9a932679470c95223cee339fdf2d65ec28964dd38a2
Sha384
45c72a0f99357ed9f546fcb21d4118034c1ce392360ed2427883e41b81e475cea89c064ec7e13d45675ac4142e503768
Sha512
53fb300de05797fe088152fc94f08b06db2024d1b19a972fd29e16966448813acf3d429d7545ac78da42e17e3c2ae14a154a527a544ac7baac2c022616bb3562
SSDeep
12288:N0Mg1UyAbaETkKCquvx3LW4sob1liARqeROoguvRHcP2Ynw7VIso:N0Mv1baETsqulfliAYEM2qwiso
TLSH
98F4F15523AAEA01E5F65FF40871D3700BB57E9DB922D3060EEAACEF7835B405921393

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CrashMonitor.CrashReportForm.resources
CrashMonitor.Properties.Resources.resources
CTT
[NBF]root.Data
WzRU
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: yXqB.pdb

Module Name

yXqB.exe

Full Name

yXqB.exe

EntryPoint

System.Void CrashMonitor.Program::Main()

Scope Name

yXqB.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yXqB

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

474

Main Method

System.Void CrashMonitor.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void CrashMonitor.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

yXqB.exe

Full Name

yXqB.exe

EntryPoint

System.Void CrashMonitor.Program::Main()

Scope Name

yXqB.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yXqB

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

474

Main Method

System.Void CrashMonitor.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void CrashMonitor.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

9920bcf33cfa8118680e801c248c8bb9 (749.57 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CrashMonitor.CrashReportForm.resources
CrashMonitor.Properties.Resources.resources
CTT
[NBF]root.Data
WzRU
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙