Suspicious
Suspect

ae5f41351a8a56ee1007e8e726459128

PE Executable
|
MD5: ae5f41351a8a56ee1007e8e726459128
|
Size: 5.46 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
ae5f41351a8a56ee1007e8e726459128
Sha1
10d577b85dd3120c9f6a857becd1e99da17df959
Sha256
2f6fa9fa9d46eda7bb675550fff9ce2b075ac46bdbf95a2e3e46aa72b06aa84c
Sha384
0f988a3c487c7b31a881e79c595aae64e8318884add9501e9f5afc5ba2ba366f40caf9f35237546363f8adde15c33ebe
Sha512
58fb10535d5a7bba767e88b0334466be392403c9b1daf335c275e238450c07d3977c1f1324221c0c67903cae107e98a9dc299c886e8cc863f126508f0e2d9e21
SSDeep
49152:6IUkFAn/2Gnw6nxwXqiMOrENcitrFkPvhGR7thSoWYfy8jg78uoX59Qq32/qenDM:6qQ/2a9Or4cW+PvkNDHm4Qq32yeDGWJ
TLSH
BB46121A36C69544D23F837489798E4267F0BA4BAF21C71EB19B17EC8F013966723763

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
7CjrXq2t0.g.resources
7CjrXq2t0.Resources.resources
cd2f09be3a37be.Resources.resources
3d61eaad0
[NBF]root.Data
3d61eaad1
[NBF]root.Data
3d61eaad10
[NBF]root.Data
3d61eaad100
[NBF]root.Data
3d61eaad101
[NBF]root.Data
3d61eaad102
[NBF]root.Data
3d61eaad103
[NBF]root.Data
3d61eaad104
[NBF]root.Data
3d61eaad105
[NBF]root.Data
3d61eaad106
[NBF]root.Data
3d61eaad107
[NBF]root.Data
3d61eaad108
[NBF]root.Data
3d61eaad109
[NBF]root.Data
3d61eaad11
[NBF]root.Data
3d61eaad110
[NBF]root.Data
3d61eaad111
[NBF]root.Data
3d61eaad112
[NBF]root.Data
3d61eaad113
[NBF]root.Data
3d61eaad114
[NBF]root.Data
3d61eaad115
[NBF]root.Data
3d61eaad116
[NBF]root.Data
3d61eaad117
[NBF]root.Data
3d61eaad118
[NBF]root.Data
3d61eaad119
[NBF]root.Data
3d61eaad12
[NBF]root.Data
3d61eaad120
[NBF]root.Data
3d61eaad121
[NBF]root.Data
3d61eaad122
[NBF]root.Data
3d61eaad123
[NBF]root.Data
3d61eaad124
[NBF]root.Data
3d61eaad125
[NBF]root.Data
3d61eaad126
[NBF]root.Data
3d61eaad127
[NBF]root.Data
3d61eaad128
[NBF]root.Data
3d61eaad129
[NBF]root.Data
3d61eaad13
[NBF]root.Data
3d61eaad130
[NBF]root.Data
3d61eaad131
[NBF]root.Data
3d61eaad132
[NBF]root.Data
3d61eaad133
[NBF]root.Data
3d61eaad134
[NBF]root.Data
3d61eaad135
[NBF]root.Data
3d61eaad136
[NBF]root.Data
3d61eaad137
[NBF]root.Data
3d61eaad138
[NBF]root.Data
3d61eaad139
[NBF]root.Data
3d61eaad14
[NBF]root.Data
3d61eaad140
[NBF]root.Data
3d61eaad141
[NBF]root.Data
3d61eaad142
[NBF]root.Data
3d61eaad143
[NBF]root.Data
3d61eaad144
[NBF]root.Data
3d61eaad145
[NBF]root.Data
3d61eaad146
[NBF]root.Data
3d61eaad147
[NBF]root.Data
3d61eaad148
[NBF]root.Data
3d61eaad149
[NBF]root.Data
3d61eaad15
[NBF]root.Data
3d61eaad150
[NBF]root.Data
3d61eaad151
[NBF]root.Data
3d61eaad152
[NBF]root.Data
3d61eaad153
[NBF]root.Data
3d61eaad154
[NBF]root.Data
3d61eaad155
[NBF]root.Data
3d61eaad156
[NBF]root.Data
3d61eaad157
[NBF]root.Data
3d61eaad158
[NBF]root.Data
3d61eaad159
[NBF]root.Data
3d61eaad16
[NBF]root.Data
3d61eaad160
[NBF]root.Data
3d61eaad161
[NBF]root.Data
3d61eaad162
[NBF]root.Data
3d61eaad163
[NBF]root.Data
3d61eaad164
[NBF]root.Data
3d61eaad165
[NBF]root.Data
3d61eaad166
[NBF]root.Data
3d61eaad167
[NBF]root.Data
3d61eaad168
[NBF]root.Data
3d61eaad169
[NBF]root.Data
3d61eaad17
[NBF]root.Data
3d61eaad170
[NBF]root.Data
3d61eaad171
[NBF]root.Data
3d61eaad172
[NBF]root.Data
3d61eaad173
[NBF]root.Data
3d61eaad174
[NBF]root.Data
3d61eaad175
[NBF]root.Data
3d61eaad176
[NBF]root.Data
3d61eaad177
[NBF]root.Data
3d61eaad178
[NBF]root.Data
3d61eaad179
[NBF]root.Data
3d61eaad18
[NBF]root.Data
3d61eaad180
[NBF]root.Data
3d61eaad181
[NBF]root.Data
3d61eaad182
[NBF]root.Data
3d61eaad183
[NBF]root.Data
3d61eaad184
[NBF]root.Data
3d61eaad185
[NBF]root.Data
3d61eaad186
[NBF]root.Data
3d61eaad187
[NBF]root.Data
3d61eaad188
[NBF]root.Data
3d61eaad189
[NBF]root.Data
3d61eaad19
[NBF]root.Data
3d61eaad190
[NBF]root.Data
3d61eaad191
[NBF]root.Data
3d61eaad192
[NBF]root.Data
3d61eaad193
[NBF]root.Data
3d61eaad194
[NBF]root.Data
3d61eaad195
[NBF]root.Data
3d61eaad196
[NBF]root.Data
3d61eaad197
[NBF]root.Data
3d61eaad198
[NBF]root.Data
3d61eaad199
[NBF]root.Data
3d61eaad2
[NBF]root.Data
3d61eaad20
[NBF]root.Data
3d61eaad200
[NBF]root.Data
3d61eaad201
[NBF]root.Data
3d61eaad202
[NBF]root.Data
3d61eaad203
[NBF]root.Data
3d61eaad204
[NBF]root.Data
3d61eaad205
[NBF]root.Data
3d61eaad206
[NBF]root.Data
3d61eaad207
[NBF]root.Data
3d61eaad208
[NBF]root.Data
3d61eaad209
[NBF]root.Data
3d61eaad21
[NBF]root.Data
3d61eaad210
[NBF]root.Data
3d61eaad211
[NBF]root.Data
3d61eaad212
[NBF]root.Data
3d61eaad213
[NBF]root.Data
3d61eaad214
[NBF]root.Data
3d61eaad215
[NBF]root.Data
3d61eaad216
[NBF]root.Data
3d61eaad217
[NBF]root.Data
3d61eaad218
[NBF]root.Data
3d61eaad219
[NBF]root.Data
3d61eaad22
[NBF]root.Data
3d61eaad220
[NBF]root.Data
3d61eaad221
[NBF]root.Data
3d61eaad222
[NBF]root.Data
3d61eaad223
[NBF]root.Data
3d61eaad224
[NBF]root.Data
3d61eaad225
[NBF]root.Data
3d61eaad226
[NBF]root.Data
3d61eaad227
[NBF]root.Data
3d61eaad228
[NBF]root.Data
3d61eaad229
[NBF]root.Data
3d61eaad23
[NBF]root.Data
3d61eaad230
[NBF]root.Data
3d61eaad231
[NBF]root.Data
3d61eaad232
[NBF]root.Data
3d61eaad233
[NBF]root.Data
3d61eaad234
[NBF]root.Data
3d61eaad235
[NBF]root.Data
3d61eaad236
[NBF]root.Data
3d61eaad237
[NBF]root.Data
3d61eaad238
[NBF]root.Data
3d61eaad239
[NBF]root.Data
3d61eaad24
[NBF]root.Data
3d61eaad240
[NBF]root.Data
3d61eaad241
[NBF]root.Data
3d61eaad242
[NBF]root.Data
3d61eaad243
[NBF]root.Data
3d61eaad244
[NBF]root.Data
3d61eaad245
[NBF]root.Data
3d61eaad246
[NBF]root.Data
3d61eaad247
[NBF]root.Data
3d61eaad248
[NBF]root.Data
3d61eaad249
[NBF]root.Data
3d61eaad25
[NBF]root.Data
3d61eaad250
[NBF]root.Data
3d61eaad251
[NBF]root.Data
3d61eaad252
[NBF]root.Data
3d61eaad253
[NBF]root.Data
3d61eaad254
[NBF]root.Data
3d61eaad255
[NBF]root.Data
3d61eaad256
[NBF]root.Data
3d61eaad257
[NBF]root.Data
3d61eaad258
[NBF]root.Data
3d61eaad259
[NBF]root.Data
3d61eaad26
[NBF]root.Data
3d61eaad260
[NBF]root.Data
3d61eaad261
[NBF]root.Data
3d61eaad262
[NBF]root.Data
3d61eaad263
[NBF]root.Data
3d61eaad264
[NBF]root.Data
3d61eaad265
[NBF]root.Data
3d61eaad266
[NBF]root.Data
3d61eaad267
[NBF]root.Data
3d61eaad268
[NBF]root.Data
3d61eaad269
[NBF]root.Data
3d61eaad27
[NBF]root.Data
3d61eaad270
[NBF]root.Data
3d61eaad271
[NBF]root.Data
3d61eaad272
[NBF]root.Data
3d61eaad273
[NBF]root.Data
3d61eaad274
[NBF]root.Data
3d61eaad275
[NBF]root.Data
3d61eaad276
[NBF]root.Data
3d61eaad277
[NBF]root.Data
3d61eaad278
[NBF]root.Data
3d61eaad279
[NBF]root.Data
3d61eaad28
[NBF]root.Data
3d61eaad280
[NBF]root.Data
3d61eaad281
[NBF]root.Data
3d61eaad282
[NBF]root.Data
3d61eaad29
[NBF]root.Data
3d61eaad3
[NBF]root.Data
3d61eaad30
[NBF]root.Data
3d61eaad31
[NBF]root.Data
3d61eaad32
[NBF]root.Data
3d61eaad33
[NBF]root.Data
3d61eaad34
[NBF]root.Data
3d61eaad35
[NBF]root.Data
3d61eaad36
[NBF]root.Data
3d61eaad37
[NBF]root.Data
3d61eaad38
[NBF]root.Data
3d61eaad39
[NBF]root.Data
3d61eaad4
[NBF]root.Data
3d61eaad40
[NBF]root.Data
3d61eaad41
[NBF]root.Data
3d61eaad42
[NBF]root.Data
3d61eaad43
[NBF]root.Data
3d61eaad44
[NBF]root.Data
3d61eaad45
[NBF]root.Data
3d61eaad46
[NBF]root.Data
3d61eaad47
[NBF]root.Data
3d61eaad48
[NBF]root.Data
3d61eaad49
[NBF]root.Data
3d61eaad5
[NBF]root.Data
3d61eaad50
[NBF]root.Data
3d61eaad51
[NBF]root.Data
3d61eaad52
[NBF]root.Data
3d61eaad53
[NBF]root.Data
3d61eaad54
[NBF]root.Data
3d61eaad55
[NBF]root.Data
3d61eaad56
[NBF]root.Data
3d61eaad57
[NBF]root.Data
3d61eaad58
[NBF]root.Data
3d61eaad59
[NBF]root.Data
3d61eaad6
[NBF]root.Data
3d61eaad60
[NBF]root.Data
3d61eaad61
[NBF]root.Data
3d61eaad62
[NBF]root.Data
3d61eaad63
[NBF]root.Data
3d61eaad64
[NBF]root.Data
3d61eaad65
[NBF]root.Data
3d61eaad66
[NBF]root.Data
3d61eaad67
[NBF]root.Data
3d61eaad68
[NBF]root.Data
3d61eaad69
[NBF]root.Data
3d61eaad7
[NBF]root.Data
3d61eaad70
[NBF]root.Data
3d61eaad71
[NBF]root.Data
3d61eaad72
[NBF]root.Data
3d61eaad73
[NBF]root.Data
3d61eaad74
[NBF]root.Data
3d61eaad75
[NBF]root.Data
3d61eaad76
[NBF]root.Data
3d61eaad77
[NBF]root.Data
3d61eaad78
[NBF]root.Data
3d61eaad79
[NBF]root.Data
3d61eaad8
[NBF]root.Data
3d61eaad80
[NBF]root.Data
3d61eaad81
[NBF]root.Data
3d61eaad82
[NBF]root.Data
3d61eaad83
[NBF]root.Data
3d61eaad84
[NBF]root.Data
3d61eaad85
[NBF]root.Data
3d61eaad86
[NBF]root.Data
3d61eaad87
[NBF]root.Data
3d61eaad88
[NBF]root.Data
3d61eaad89
[NBF]root.Data
3d61eaad9
[NBF]root.Data
3d61eaad90
[NBF]root.Data
3d61eaad91
[NBF]root.Data
3d61eaad92
[NBF]root.Data
3d61eaad93
[NBF]root.Data
3d61eaad94
[NBF]root.Data
3d61eaad95
[NBF]root.Data
3d61eaad96
[NBF]root.Data
3d61eaad97
[NBF]root.Data
3d61eaad98
[NBF]root.Data
3d61eaad99
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

7CjrXq2t0

Full Name

7CjrXq2t0

EntryPoint

System.Void 7CjrXq2t0.Kk5izeS::1pdGg5Nw0()

Scope Name

7CjrXq2t0

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7CjrXq2t0

Assembly Version

18.25.23.167

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 7CjrXq2t0.Kk5izeS::1pdGg5Nw0()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 7CjrXq2t0.Kk5izeS::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 7CjrXq2t0.Kk5izeS call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 7CjrXq2t0.Kk5izeS stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 7CjrXq2t0.6Xetg9::Bwa48sEgr(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 7CjrXq2t0.Yq8bnDf1Z7qc5o/4Baqf.qt4WE2::1Zdnb6fP(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

Module Name

7CjrXq2t0

Full Name

7CjrXq2t0

EntryPoint

System.Void 7CjrXq2t0.Kk5izeS::1pdGg5Nw0()

Scope Name

7CjrXq2t0

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7CjrXq2t0

Assembly Version

18.25.23.167

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 7CjrXq2t0.Kk5izeS::1pdGg5Nw0()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 7CjrXq2t0.Kk5izeS::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 7CjrXq2t0.Kk5izeS call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 7CjrXq2t0.Kk5izeS stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 7CjrXq2t0.6Xetg9::Bwa48sEgr(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 7CjrXq2t0.Yq8bnDf1Z7qc5o/4Baqf.qt4WE2::1Zdnb6fP(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

ae5f41351a8a56ee1007e8e726459128 (5.46 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙