Suspicious
Suspect

9ed0d8c88bffa379f5df36202d605cc4

PE Executable
|
MD5: 9ed0d8c88bffa379f5df36202d605cc4
|
Size: 1.27 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
9ed0d8c88bffa379f5df36202d605cc4
Sha1
0819d433f5cab4de26c98ca3b0c3b087e7cb529a
Sha256
495ebfa4a23110b80b574a0dd8cf31022b207c50d2623ce9ac5156bc7660669e
Sha384
60250b1f42d21f5f962a599541e472f69e3d78962f863a63ee02fcebc1fb4b904931c9a3f163751b1407fa1bc50d3af3
Sha512
e0d045f6a9cc39be9aeae1cf61399f5384b351edd46eeb40746febf7dfca5e828f5cf879c373a8dc7747702d88db1fb9f206fbeae845c4f636a5c830d3042b19
SSDeep
12288:avezD6ZtwCj87r4YSkIv8Xu0/9gZr4z8hsbG38hQY/pUjvz8+DY1GKQzSnMgwe+C:wqD64Cj8YD0e0y2i386YhUjYQgZQzJA
TLSH
2B45CF1A27D96EF0E17B8F3192B4025047F0B60BD222E75E6994F3F9CEE2B495512363

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
TetraSite.demandflatteningrules
Yk2qye.Wzy30cJyaT.resources
a0361056af2e02.Resources.resources
40d2be740
[NBF]root.Data
40d2be741
[NBF]root.Data
40d2be7410
[NBF]root.Data
40d2be7411
[NBF]root.Data
40d2be7412
[NBF]root.Data
40d2be7413
[NBF]root.Data
40d2be7414
[NBF]root.Data
40d2be7415
[NBF]root.Data
40d2be7416
[NBF]root.Data
40d2be7417
[NBF]root.Data
40d2be7418
[NBF]root.Data
40d2be7419
[NBF]root.Data
40d2be742
[NBF]root.Data
40d2be7420
[NBF]root.Data
40d2be7421
[NBF]root.Data
40d2be7422
[NBF]root.Data
40d2be7423
[NBF]root.Data
40d2be7424
[NBF]root.Data
40d2be7425
[NBF]root.Data
40d2be7426
[NBF]root.Data
40d2be7427
[NBF]root.Data
40d2be7428
[NBF]root.Data
40d2be7429
[NBF]root.Data
40d2be743
[NBF]root.Data
40d2be7430
[NBF]root.Data
40d2be7431
[NBF]root.Data
40d2be7432
[NBF]root.Data
40d2be7433
[NBF]root.Data
40d2be7434
[NBF]root.Data
40d2be7435
[NBF]root.Data
40d2be7436
[NBF]root.Data
40d2be7437
[NBF]root.Data
40d2be7438
[NBF]root.Data
40d2be7439
[NBF]root.Data
40d2be744
[NBF]root.Data
40d2be7440
[NBF]root.Data
40d2be7441
[NBF]root.Data
40d2be7442
[NBF]root.Data
40d2be745
[NBF]root.Data
40d2be746
[NBF]root.Data
40d2be747
[NBF]root.Data
40d2be748
[NBF]root.Data
40d2be749
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Yk2qye

Full Name

Yk2qye

EntryPoint

System.Void Yk2qye.qo8A5dPtxE6j/Qz0dmRc5.bMi15iGxpKj::4mwAf()

Scope Name

Yk2qye

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yk2qye

Assembly Version

16.13.41.222

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1175

Main Method

System.Void Yk2qye.qo8A5dPtxE6j/Qz0dmRc5.bMi15iGxpKj::4mwAf()

Main IL Instruction Count

32

Main IL

nop <null> nop <null> ldc.i4.s 20 stloc.0 <null> newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.1 <null> ldloc.0 <null> stloc.2 <null> ldc.i4.1 <null> stloc.3 <null> br.s IL_001D: ldloc.3 ldloc.1 <null> ldloc.3 <null> callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.3 <null> ldc.i4.1 <null> add.ovf <null> stloc.3 <null> ldloc.3 <null> ldloc.2 <null> ble.s IL_0011: ldloc.1 ldstr demandflatteningrules call System.Void Yk2qye.5WpeDk7mkFq8R::8g_EwBt0Zy4mb(System.String) nop <null> leave.s IL_003B: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003B: nop nop <null> ret <null>

Module Name

Yk2qye

Full Name

Yk2qye

EntryPoint

System.Void Yk2qye.qo8A5dPtxE6j/Qz0dmRc5.bMi15iGxpKj::4mwAf()

Scope Name

Yk2qye

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yk2qye

Assembly Version

16.13.41.222

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1175

Main Method

System.Void Yk2qye.qo8A5dPtxE6j/Qz0dmRc5.bMi15iGxpKj::4mwAf()

Main IL Instruction Count

32

Main IL

nop <null> nop <null> ldc.i4.s 20 stloc.0 <null> newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.1 <null> ldloc.0 <null> stloc.2 <null> ldc.i4.1 <null> stloc.3 <null> br.s IL_001D: ldloc.3 ldloc.1 <null> ldloc.3 <null> callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.3 <null> ldc.i4.1 <null> add.ovf <null> stloc.3 <null> ldloc.3 <null> ldloc.2 <null> ble.s IL_0011: ldloc.1 ldstr demandflatteningrules call System.Void Yk2qye.5WpeDk7mkFq8R::8g_EwBt0Zy4mb(System.String) nop <null> leave.s IL_003B: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003B: nop nop <null> ret <null>

9ed0d8c88bffa379f5df36202d605cc4 (1.27 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙