Suspicious
Suspect

a80e4f4d318805db0a195e43b3d8c2da

PE Executable
|
MD5: a80e4f4d318805db0a195e43b3d8c2da
|
Size: 488.96 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
a80e4f4d318805db0a195e43b3d8c2da
Sha1
40b9c76cc9434fce19022a867bd566697a789d19
Sha256
d28d2788b9d5b476e71fb63b71e36b3eb36fed4ca0152f36fa6f00aab857543f
Sha384
a64cb7a454de9ed5f466a69797e82003ef834dda73730e75ef0aa2adfd4067d27f75a229b71f744afa20826841f1faf1
Sha512
a979bfb3ef4114f4b7881656c5647d4a1a3b3777438c7fb5b2b2d4fa29f51b875592e72dd361a0b09755636b7543a9eee0ea8eb0d5aefcf3ee04e2ea9b73b656
SSDeep
12288:Mpu0rlYENKMi5uUUsF0mAYic3EWp0ehbbD+dJS:ErlYKtouUipYtnbb
TLSH
E8A4BED43A21732ECDA28931D968ECB491E42C797206BAE354DF3B5B794C151DE0CFA2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PegSolitaire.StartMenuFormular.resources
PegSolitaire.Properties.Resources.resources
V6
[NBF]root.Data
dagJ
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

lLez.exe

Full Name

lLez.exe

EntryPoint

System.Void PegSolitaire.Program::Main()

Scope Name

lLez.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

lLez

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

117

Main Method

System.Void PegSolitaire.Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> ldc.i4 1612691658 ldc.i4 2037867350 xor <null> dup <null> stloc.0 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0070: ret nop <null> ldloc.0 <null> ldc.i4 -1841116070 mul <null> ldc.i4 938304502 xor <null> br.s IL_0006: ldc.i4 2037867350 nop <null> newobj System.Void PegSolitaire.StartMenuFormular::.ctor() call System.Void PegSolitaire.Program::‏‎‍‭‮‫‬‍‪‭‫‭‏‬‭‮‫‮‮‪‌​‍‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 438664906 mul <null> ldc.i4 55544112 xor <null> br.s IL_0006: ldc.i4 2037867350 call System.Void PegSolitaire.Program::‫​‍‫‭‪‌‌‏‪‭‫‏‌‬‏‎​‮‪‬‮‮‌‮() nop <null> ldc.i4.0 <null> call System.Void PegSolitaire.Program::‮‏‪‎‍‍‭‪‪‬‍‎‬​​‫‮‮​‎‪‮(System.Boolean) ldloc.0 <null> ldc.i4 -2018400454 mul <null> ldc.i4 85040798 xor <null> br.s IL_0006: ldc.i4 2037867350 ret <null>

Module Name

lLez.exe

Full Name

lLez.exe

EntryPoint

System.Void PegSolitaire.Program::Main()

Scope Name

lLez.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

lLez

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

117

Main Method

System.Void PegSolitaire.Program::Main()

Main IL Instruction Count

37

Main IL

nop <null> ldc.i4 1612691658 ldc.i4 2037867350 xor <null> dup <null> stloc.0 <null> ldc.i4.5 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0070: ret nop <null> ldloc.0 <null> ldc.i4 -1841116070 mul <null> ldc.i4 938304502 xor <null> br.s IL_0006: ldc.i4 2037867350 nop <null> newobj System.Void PegSolitaire.StartMenuFormular::.ctor() call System.Void PegSolitaire.Program::‏‎‍‭‮‫‬‍‪‭‫‭‏‬‭‮‫‮‮‪‌​‍‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 438664906 mul <null> ldc.i4 55544112 xor <null> br.s IL_0006: ldc.i4 2037867350 call System.Void PegSolitaire.Program::‫​‍‫‭‪‌‌‏‪‭‫‏‌‬‏‎​‮‪‬‮‮‌‮() nop <null> ldc.i4.0 <null> call System.Void PegSolitaire.Program::‮‏‪‎‍‍‭‪‪‬‍‎‬​​‫‮‮​‎‪‮(System.Boolean) ldloc.0 <null> ldc.i4 -2018400454 mul <null> ldc.i4 85040798 xor <null> br.s IL_0006: ldc.i4 2037867350 ret <null>

a80e4f4d318805db0a195e43b3d8c2da (488.96 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙