Suspicious
Suspect

a47a8b08c2a63d3bda962afba7b7de4f

PE Executable
|
MD5: a47a8b08c2a63d3bda962afba7b7de4f
|
Size: 1.04 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
a47a8b08c2a63d3bda962afba7b7de4f
Sha1
dc4bd6d2fccd8a1af3343cfa474c7b70b5f943df
Sha256
d9dd1ad6d094d10dc2ad9b373a5fa5c68be03eebe770471458bbe91fe92c65c7
Sha384
ad99f0d0a2edecafd460a041220f4618871ba51a685d25660446aadac1259c0454cac73f3b02b8110a8c12d81a00f399
Sha512
5eb16a4407da143108b4ce36f4106393450ecadd3931c2a0a995d904f948b3050c79513ae65844d2384241ecfce310e8c8e0df6fbce562d9dacf2acc681742ef
SSDeep
24576:baRQ0IyoCPrDFjx4aZvUq0o7ySgE8zuG/x:OZI4F3L0tg8x
TLSH
1D25CF983EC1B98EC0F3CA768DA0DD709E147DE69327C217A9DB1D9FB81D552CE041A2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
QTbw
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

hPwQ.exe

Full Name

hPwQ.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

hPwQ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hPwQ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

63

Main IL

nop <null> call System.Void EventLogAnalyzer.Program::‫‏‎‏‫‎‍‮‌​‏‫‌‌‮‎​‍‫‬‪‭‫‮‭‌‮() nop <null> ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‌‎‫‎‏‎‌‏‍‍​‍‏‭‎‪‫‫‌‏‪‍‎‮‍‍‮‮(System.Boolean) nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‭‪‭​​‮‪‬‎‍‌‪‬‫​‮‏‪‭‫‭‏‮‭​‮(System.Windows.Forms.Form) ldc.i4 1328915496 ldc.i4 2038251811 xor <null> dup <null> stloc.1 <null> ldc.i4.4 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_005F: leave.s IL_00BA nop <null> ldloc.1 <null> ldc.i4 1462281465 mul <null> ldc.i4 24580874 xor <null> br.s IL_001E: ldc.i4 2038251811 nop <null> ldloc.1 <null> ldc.i4 -147960854 mul <null> ldc.i4 -1076036110 xor <null> br.s IL_001E: ldc.i4 2038251811 leave.s IL_00BA: ret stloc.0 <null> nop <null> ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‏‎​‪​‪‪‍‍‌‏‮‬‎‏‬‏‎​‌‬​​‬‌‎‭​‎‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‫‮‎‎‮‏‪‭‎‮‬​‏‪‫‪‌‌‭‮‮‬‏‌‬‌‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‮‏‌‎​‬‌‪‫‌‭​‪‪‌‬‭‎​​‫‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldc.i4 1975010628 ldc.i4 2038251811 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00B8: leave.s IL_00BA nop <null> ldloc.1 <null> ldc.i4 1264689027 mul <null> ldc.i4 -774627107 xor <null> br.s IL_008B: ldc.i4 2038251811 leave.s IL_00BA: ret ret <null>

Module Name

hPwQ.exe

Full Name

hPwQ.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

hPwQ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

hPwQ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

63

Main IL

nop <null> call System.Void EventLogAnalyzer.Program::‫‏‎‏‫‎‍‮‌​‏‫‌‌‮‎​‍‫‬‪‭‫‮‭‌‮() nop <null> ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‌‎‫‎‏‎‌‏‍‍​‍‏‭‎‪‫‫‌‏‪‍‎‮‍‍‮‮(System.Boolean) nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‭‪‭​​‮‪‬‎‍‌‪‬‫​‮‏‪‭‫‭‏‮‭​‮(System.Windows.Forms.Form) ldc.i4 1328915496 ldc.i4 2038251811 xor <null> dup <null> stloc.1 <null> ldc.i4.4 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_005F: leave.s IL_00BA nop <null> ldloc.1 <null> ldc.i4 1462281465 mul <null> ldc.i4 24580874 xor <null> br.s IL_001E: ldc.i4 2038251811 nop <null> ldloc.1 <null> ldc.i4 -147960854 mul <null> ldc.i4 -1076036110 xor <null> br.s IL_001E: ldc.i4 2038251811 leave.s IL_00BA: ret stloc.0 <null> nop <null> ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‏‎​‪​‪‪‍‍‌‏‮‬‎‏‬‏‎​‌‬​​‬‌‎‭​‎‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‫‮‎‎‮‏‪‭‎‮‬​‏‪‫‪‌‌‭‮‮‬‏‌‬‌‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‮‏‌‎​‬‌‪‫‌‭​‪‪‌‬‭‎​​‫‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldc.i4 1975010628 ldc.i4 2038251811 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00B8: leave.s IL_00BA nop <null> ldloc.1 <null> ldc.i4 1264689027 mul <null> ldc.i4 -774627107 xor <null> br.s IL_008B: ldc.i4 2038251811 leave.s IL_00BA: ret ret <null>

a47a8b08c2a63d3bda962afba7b7de4f (1.04 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙