Suspicious
Suspect

a451767c4c14024886eb3ddc3fd30c0e

PE Executable
|
MD5: a451767c4c14024886eb3ddc3fd30c0e
|
Size: 598.02 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
a451767c4c14024886eb3ddc3fd30c0e
Sha1
35fd1334ed151432e04cadf2844c5c14a7965c96
Sha256
27af0f60f3069416ee2be26ee18589448518135832e18ae26e867a95d22d8065
Sha384
b8669251fe31a8a0ba3a1ee538255c1fae65dbf5f5c8b41e96ced38e66ddde7c8cb57fed4877d96a30110269dcc2e0d2
Sha512
3ad5bc7abd26e67f0cda7d21936334ae9abad800aa8bd2ff5f25db2cad612bc7d176ae2ba2f7177baedcd747f34904c977b67b38c73c997246db5ad3db0d2f57
SSDeep
12288:HuH5T30vrPXJ8+bVtQSy2NJquSNoSO7xKqXD:HuHF+r/JNVtQ3qgs1
TLSH
89D401583B15EA46C9742BB42A70E274077D6DAEA820E30B9EDA3DEF7476B010C457D3
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConvert.BidirectionalConverterForm.resources
UnitConvert.Properties.Resources.resources
Epgw
[NBF]root.Data
[NBF]root.Data-preview.png
de
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ClSB.pdb

Module Name

ClSB.exe

Full Name

ClSB.exe

EntryPoint

System.Void UnitConvert.Program::Main()

Scope Name

ClSB.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ClSB

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

387

Main Method

System.Void UnitConvert.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void UnitConvert.MainMenuForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

a451767c4c14024886eb3ddc3fd30c0e (598.02 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙