Suspicious
Suspect

Spreadsheet.exe

PE Executable
|
MD5: a249a2280a9bc5af6263ad3cc77a22d4
|
Size: 809.98 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
a249a2280a9bc5af6263ad3cc77a22d4
Sha1
4e3d499def302685179f52c4a8f4fd434361ae8a
Sha256
fb950059d4dbf088a3f81339ba49bb503db94d915f1dc5707eaed1bffe7ba263
Sha384
38a5661b39d873d767986e347fd1b4291a8a58c8ebce14a571e8783b4e0886080fd87bef1526cf0b140be9f92045b8b7
Sha512
043f84c4e52a55ce781819f7b90aa2cb0906450d9cc92031a6a5ee1e030e3356c856aba8f50a9e77adcbfbc83d7d0150b0bd376b8f808762255054768d918af6
SSDeep
24576:QqC5abyBNPyr/pumXHAuHtQNluwLVuVgdHfmnf2:fbvr/pJAuNmQSVuGmf
TLSH
3505DF9C3251B59FC493C9318DA4ED70AA247DAA930BD20390D71DABBD0E99BDF141F2

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C++ v6.0 DLL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSVViewer.Forms.MainForm.resources
CSVViewer.Properties.Resources.resources
KS
[NBF]root.Data
SRxB
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

ucTW.exe

Full Name

ucTW.exe

EntryPoint

System.Void CSVViewer.Program::Main()

Scope Name

ucTW.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ucTW

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

183

Main Method

System.Void CSVViewer.Program::Main()

Main IL Instruction Count

43

Main IL

nop <null> ldc.i4 -1245001980 ldc.i4 -623188456 xor <null> dup <null> stloc.0 <null> ldc.i4.6 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0083: ret nop <null> ldloc.0 <null> ldc.i4 -231718416 mul <null> ldc.i4 2108801866 xor <null> br.s IL_0006: ldc.i4 -623188456 nop <null> ldc.i4.0 <null> call System.Void CSVViewer.Program::‎‭‮‪‎​‌‪​‪​‭‎‪​‏​‫‪‪‬‎‪‮‏‏‪‎‮(System.Boolean) ldloc.0 <null> ldc.i4 55895918 mul <null> ldc.i4 1616117381 xor <null> br.s IL_0006: ldc.i4 -623188456 nop <null> newobj System.Void CSVViewer.Forms.MainForm::.ctor() call System.Void CSVViewer.Program::‎​‍‪‏​‮‏‪‭‭‭‬​‬‮​‬‫‍‍​‏‎‍‬‌‌‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1104787523 mul <null> ldc.i4 1771559466 xor <null> br.s IL_0006: ldc.i4 -623188456 call System.Void CSVViewer.Program::‫‫​‪‎‌‫‍​‬‮​‪​‬‭‌‪‎‏‮‬‮‫‮() ldloc.0 <null> ldc.i4 -1704156889 mul <null> ldc.i4 1329810689 xor <null> br.s IL_0006: ldc.i4 -623188456 ret <null>

Module Name

ucTW.exe

Full Name

ucTW.exe

EntryPoint

System.Void CSVViewer.Program::Main()

Scope Name

ucTW.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ucTW

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

183

Main Method

System.Void CSVViewer.Program::Main()

Main IL Instruction Count

43

Main IL

nop <null> ldc.i4 -1245001980 ldc.i4 -623188456 xor <null> dup <null> stloc.0 <null> ldc.i4.6 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0083: ret nop <null> ldloc.0 <null> ldc.i4 -231718416 mul <null> ldc.i4 2108801866 xor <null> br.s IL_0006: ldc.i4 -623188456 nop <null> ldc.i4.0 <null> call System.Void CSVViewer.Program::‎‭‮‪‎​‌‪​‪​‭‎‪​‏​‫‪‪‬‎‪‮‏‏‪‎‮(System.Boolean) ldloc.0 <null> ldc.i4 55895918 mul <null> ldc.i4 1616117381 xor <null> br.s IL_0006: ldc.i4 -623188456 nop <null> newobj System.Void CSVViewer.Forms.MainForm::.ctor() call System.Void CSVViewer.Program::‎​‍‪‏​‮‏‪‭‭‭‬​‬‮​‬‫‍‍​‏‎‍‬‌‌‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1104787523 mul <null> ldc.i4 1771559466 xor <null> br.s IL_0006: ldc.i4 -623188456 call System.Void CSVViewer.Program::‫‫​‪‎‌‫‍​‬‮​‪​‬‭‌‪‎‏‮‬‮‫‮() ldloc.0 <null> ldc.i4 -1704156889 mul <null> ldc.i4 1329810689 xor <null> br.s IL_0006: ldc.i4 -623188456 ret <null>

Spreadsheet.exe (809.98 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙