Suspicious
Suspect

a7bded33199132356887d7b258c9fb47

PE Executable
|
MD5: a7bded33199132356887d7b258c9fb47
|
Size: 21.5 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
a7bded33199132356887d7b258c9fb47
Sha1
90ac8a2d31c67e7b843fe120da7d0d1c3fe962eb
Sha256
97dd1ff0394cec09c7c09b71d7dd7e646630d3351c3d6f55e462a8b0bebaaace
Sha384
d10a82ebfdec70bcdf93c2040c3c44598c71f9729f85bdc7b60efb088ecc7ceb6e8c1a0380a4654971475fd9d7f25e08
Sha512
23e33ade6c4fd022bc4f3acd3870bde7433be789eee27e70191f09914a22c330cd4c22d8da785763aa2410461fd09123c97cc6464c9360711b27cff6814c43b4
SSDeep
384:bF3fOlaKRqjXs10GHqDS17nxKQewdn9Bn8H4Rl/CSWeCly8g3uqLVQ:Vf0aKRqAHqDa7AYnbVaSxCEBO
TLSH
B3A2F542F78D4664F563CB3DD8FBD40D0724A6926ED3CD1A38CB23066C12367EA9725A

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Module Name

INV-23060005-JMCB-2100653.exe

Full Name

INV-23060005-JMCB-2100653.exe

EntryPoint

System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::ConcatPublisher()

Scope Name

INV-23060005-JMCB-2100653.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

INV-23060005-JMCB-2100653

Assembly Version

1.0.7329.12321

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

5

Main Method

System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::ConcatPublisher()

Main IL Instruction Count

31

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0053: ret ldsfld System.Action`1<System.IO.MemoryStream> INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::m_TransformablePublisher dup <null> brtrue IL_006A: call System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::CollectConvertiblePublisher(System.Action`1<System.IO.MemoryStream>) pop <null> ldc.i4 1 ldsfld <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a} <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d209b69652a846c4b37489a01dee121d ldfld System.Int32 <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_684a775a93d1482db71fed337deb3933 brtrue IL_0012: switch(IL_0053,IL_0054,IL_0028) pop <null> ldc.i4 1 br IL_0012: switch(IL_0053,IL_0054,IL_0028) ret <null> ldsfld INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::_ConcreteCommand ldftn System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::SetupPublisher(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::m_TransformablePublisher call System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::CollectConvertiblePublisher(System.Action`1<System.IO.MemoryStream>) ldc.i4 0 ldsfld <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a} <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d209b69652a846c4b37489a01dee121d ldfld System.Int32 <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d411526fa4744c66bdcb5b82f8fe898c brfalse IL_0012: switch(IL_0053,IL_0054,IL_0028) pop <null> ldc.i4 0 br IL_0012: switch(IL_0053,IL_0054,IL_0028)

Module Name

INV-23060005-JMCB-2100653.exe

Full Name

INV-23060005-JMCB-2100653.exe

EntryPoint

System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::ConcatPublisher()

Scope Name

INV-23060005-JMCB-2100653.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

INV-23060005-JMCB-2100653

Assembly Version

1.0.7329.12321

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

5

Main Method

System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::ConcatPublisher()

Main IL Instruction Count

31

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0053: ret ldsfld System.Action`1<System.IO.MemoryStream> INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::m_TransformablePublisher dup <null> brtrue IL_006A: call System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::CollectConvertiblePublisher(System.Action`1<System.IO.MemoryStream>) pop <null> ldc.i4 1 ldsfld <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a} <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d209b69652a846c4b37489a01dee121d ldfld System.Int32 <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_684a775a93d1482db71fed337deb3933 brtrue IL_0012: switch(IL_0053,IL_0054,IL_0028) pop <null> ldc.i4 1 br IL_0012: switch(IL_0053,IL_0054,IL_0028) ret <null> ldsfld INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::_ConcreteCommand ldftn System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::SetupPublisher(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher/<>c::m_TransformablePublisher call System.Void INV-23060005-JMCB-2100653.Publishing.AutomatablePublisher::CollectConvertiblePublisher(System.Action`1<System.IO.MemoryStream>) ldc.i4 0 ldsfld <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a} <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d209b69652a846c4b37489a01dee121d ldfld System.Int32 <Module>{8d639a35-1c24-4cc5-93f3-915995d6834a}::m_d411526fa4744c66bdcb5b82f8fe898c brfalse IL_0012: switch(IL_0053,IL_0054,IL_0028) pop <null> ldc.i4 0 br IL_0012: switch(IL_0053,IL_0054,IL_0028)

a7bded33199132356887d7b258c9fb47 (21.5 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙