Suspicious
Suspect

a822f66ceeff72f1cb8a3c5a2dd350e7

PE Executable
|
MD5: a822f66ceeff72f1cb8a3c5a2dd350e7
|
Size: 888.83 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
a822f66ceeff72f1cb8a3c5a2dd350e7
Sha1
c785dd0147b41454ae91e0d887fdd5167c3cad64
Sha256
b92ba639eab5cffac0ba3cd2e1ea98448be3063b2dd43a6e102e284734f9cb4f
Sha384
9c4e233f62c65aa9caaf1cf3504b6113b6b903e8c8422d609d359b9f0cae2b1e8ab71ddd88b1e28aba25776762fafb66
Sha512
cf20e9ac4f9e279eec747e040e88614921ad369744a6df8e50c9ad8eed9d83f065a70e8f0b335eb337971bbcbdf5bb400ff4f861c6f7404676fbc969b8ba62ed
SSDeep
12288:0fMG4BQaKqOZQ8M5jW4aHy54G5GAO57EQB7VfL1vBkbtpw9wjdGtYXwgltxn/+u7:IoqRRQ3jPaHy9GAojrBkh9dG0wgltF/
TLSH
5415CFAC3254B59EC553CE728E74DC70AA606DAA9707C20395D71DAFB81DA97CF002E3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
anxk
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

BzQE.exe

Full Name

BzQE.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

BzQE.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

BzQE

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

57

Main IL

nop <null> call System.Void EventLogAnalyzer.Program::‬‮​‏‮‫‌‭‍‎‮‎‌‮‎‎‬‎​‫‫‮‎‌‎‪‎‏‮() nop <null> ldc.i4 -1001627956 ldc.i4 -585969340 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_003E: nop ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‍‫‌‪‌‌‫‪‎‏‫‭‭‫‮​‫​‬‮(System.Boolean) ldloc.1 <null> ldc.i4 -1763846154 mul <null> ldc.i4 -449454830 xor <null> br.s IL_000C: ldc.i4 -585969340 nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‎‌‬‏‭‎‎‭‮​‎​‎​‬‬‪‭‏‫‌‬‍‌​‪‎‮(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_00A7: ret stloc.0 <null> nop <null> ldc.i4 -1647072458 ldc.i4 -585969340 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00A4: nop ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‌​‪‌‌‍‎‭‎‭‪​‪‏‮‮‌‭‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‌‬‬‬‍‫‭‏‬‮‏‍‏‭‫‎‌‍‪‍‎‭‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‎‫‪‬‬‪‍‬‏‌‏‍‍​‪‪‎‍‎‭‬‌‏‭‮​‪‍‍‫‪‮‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldloc.1 <null> ldc.i4 59043089 mul <null> ldc.i4 522138332 xor <null> br.s IL_0055: ldc.i4 -585969340 nop <null> leave.s IL_00A7: ret ret <null>

Module Name

BzQE.exe

Full Name

BzQE.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

BzQE.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

BzQE

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

57

Main IL

nop <null> call System.Void EventLogAnalyzer.Program::‬‮​‏‮‫‌‭‍‎‮‎‌‮‎‎‬‎​‫‫‮‎‌‎‪‎‏‮() nop <null> ldc.i4 -1001627956 ldc.i4 -585969340 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_003E: nop ldc.i4.0 <null> call System.Void EventLogAnalyzer.Program::‍‫‌‪‌‌‫‪‎‏‫‭‭‫‮​‫​‬‮(System.Boolean) ldloc.1 <null> ldc.i4 -1763846154 mul <null> ldc.i4 -449454830 xor <null> br.s IL_000C: ldc.i4 -585969340 nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void EventLogAnalyzer.Program::‎‌‬‏‭‎‎‭‮​‎​‎​‬‬‪‭‏‫‌‬‍‌​‪‎‮(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_00A7: ret stloc.0 <null> nop <null> ldc.i4 -1647072458 ldc.i4 -585969340 xor <null> dup <null> stloc.1 <null> ldc.i4.3 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_00A4: nop ldstr An unexpected error occurred: ldloc.0 <null> call System.String EventLogAnalyzer.Program::‌​‪‌‌‍‎‭‎‭‪​‪‏‮‮‌‭‮(System.Exception) ldstr The application will now close. call System.String EventLogAnalyzer.Program::‌‬‬‬‍‫‭‏‬‮‏‍‏‭‫‎‌‍‪‍‎‭‮(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult EventLogAnalyzer.Program::‎‫‪‬‬‪‍‬‏‌‏‍‍​‪‪‎‍‎‭‬‌‏‭‮​‪‍‍‫‪‮‮(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> ldloc.1 <null> ldc.i4 59043089 mul <null> ldc.i4 522138332 xor <null> br.s IL_0055: ldc.i4 -585969340 nop <null> leave.s IL_00A7: ret ret <null>

a822f66ceeff72f1cb8a3c5a2dd350e7 (888.83 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙