Suspicious
Suspect

9dd73b58633b79e2966cca8fcada2801

PE Executable
|
MD5: 9dd73b58633b79e2966cca8fcada2801
|
Size: 592.9 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
9dd73b58633b79e2966cca8fcada2801
Sha1
a249be54f20539c42eecf63955a66111c3423096
Sha256
f239532b415d0769dea6827221c226555e1c4bda21ecd050041d829021c52d52
Sha384
d7ca9c13cdeb2cb1a7af09f1f627dd422583d1321cfe53da1743e4437c1b63e3d4028f5776484c02260132b6e4549fb8
Sha512
62c2d30c26b24f72ed2519d174880ca92691b643d1a1cb12b836745744ff46c84e88f62d202ebb91a0252e9fdb83eb4890d77fec4845e07e684cc28a2cfb08c8
SSDeep
12288:vLURvSuooKcMP0hFU8vZCsQR8c4YdJ+ixvkz8IEiTGJnOj:gouoCF/ZCWc4OBcz8CqxO
TLSH
71C402542B6DCB57D8699BF12920E2B127B51D4FA012E61ECFDAFDEB34037118980B63
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SlotMachine.SlotDisplay.resources
SlotMachine.Properties.Resources.resources
BQmsZz
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: yqZInY.pdb

Module Name

yqZInY.exe

Full Name

yqZInY.exe

EntryPoint

System.Void SlotMachine.Program::Main()

Scope Name

yqZInY.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

yqZInY

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

374

Main Method

System.Void SlotMachine.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void SlotMachine.SlotDisplay::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

9dd73b58633b79e2966cca8fcada2801 (592.9 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙