Suspicious
Suspect

ab525145e57509b5284bfafcf339ad45

PE Executable
MD5: ab525145e57509b5284bfafcf339ad45
Size: 1.61 MB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
ab525145e57509b5284bfafcf339ad45
Sha1
f576ede4e8e19128e703880f11460a4e35f0420a
Sha256
c8b4ce8bd2ae8e48dc2ab2d322faca65c673312dfa22751877e97426cb7b760e
Sha384
045e9c3faf2a8de7043dc027a6d3d9fbfa67048800ca85211446def2c1e48e0b9a2317f92e1ad975abb457a5344ebfdc
Sha512
12120822a2fa2195ec6acc39a281117396e02853f5641f1dd7c6c806c78ddf1d982bf8e7c98b79bf18a85b7189b35a5ba82e1256b31fbdfdbe93776ec0aff59e
SSDeep
24576:x63KOepcDacYa3ku5JdHtKjtdyXaa5JgYVYA93ebSXzoEQ/JgVt1wt4:U6JpcfYaNSvyXDgYVY7WX08z
TLSH
0C7502182259DF02DDD90FB2C875E2F063746DC9E821C2879EE7BEDB76757416E002A2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BoneDice.Properties.Resources.resources
HAjR
[NBF]root.Data
[NBF]root.Data-preview.png
wck
[NBF]root.Data
BoneDice.TurnierForm.resources
$this.Icon
[NBF]root.IconData
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

qoEH.exe

Full Name

qoEH.exe

EntryPoint

System.Void BoneDice.Program::Main()

Scope Name

qoEH.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

qoEH

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

396

Main Method

System.Void BoneDice.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void BoneDice.SchenkeForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

ab525145e57509b5284bfafcf339ad45 (1.61 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙