Suspicious
Suspect

af683b3778c6409cccf7fd882f1cc12b

PE Executable
|
MD5: af683b3778c6409cccf7fd882f1cc12b
|
Size: 1.37 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
af683b3778c6409cccf7fd882f1cc12b
Sha1
4c59f60c1f259e20066ca44031893b17de4a1912
Sha256
ec4b24668029c981793e06e4a1942a1fe2e9c0942ca6f9f009ca852321d70fed
Sha384
51c6e70eb46d5130143478f78381127ff8d4abb0527493a9336f36788c65254d9b05c2b332b39835bb47058f13082d0b
Sha512
5e6f28cce99b25586fe4e21bb382ed5c200c8658492424a832fc0f1c4adf358011110e443b6e117d9ec627a2d52e0404820e78657cd1ce7f6ae7aa0e661efaa4
SSDeep
24576:eOhrvm4fr1G+S5NjgkxyWHtlPVRl6FrLJAW2ppo/sovsJG/buNmmg50LsO:+4fro+S51yetlHlErLJAWUXo/280L9
TLSH
0B5533C93EB986EFDC599F7294243FB00778F6C6B232E9B0BD1CD1B968513868490947

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Efeswee.Properties.Resources.resources
Ypuevahf
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Vmqsr.exe

Full Name

Vmqsr.exe

EntryPoint

System.Void Efeswee.Idltuecy::Main()

Scope Name

Vmqsr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Vmqsr

Assembly Version

1.0.573.28338

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

9

Main Method

System.Void Efeswee.Idltuecy::Main()

Main IL Instruction Count

5

Main IL

newobj System.Void Efeswee.Ctmyteg::.ctor() call System.Byte[] Efeswee.Ctmyteg::Xyqwcrqfbd() call System.Byte[] Efeswee.Nvzceqwbhdj::Vdpyebzwpxc(System.Byte[]) call System.Void Efeswee.Osadkmdrhi::Dzpnyvtmsld(System.Byte[]) ret <null>

Module Name

Vmqsr.exe

Full Name

Vmqsr.exe

EntryPoint

System.Void Efeswee.Idltuecy::Main()

Scope Name

Vmqsr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Vmqsr

Assembly Version

1.0.573.28338

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

9

Main Method

System.Void Efeswee.Idltuecy::Main()

Main IL Instruction Count

5

Main IL

newobj System.Void Efeswee.Ctmyteg::.ctor() call System.Byte[] Efeswee.Ctmyteg::Xyqwcrqfbd() call System.Byte[] Efeswee.Nvzceqwbhdj::Vdpyebzwpxc(System.Byte[]) call System.Void Efeswee.Osadkmdrhi::Dzpnyvtmsld(System.Byte[]) ret <null>

af683b3778c6409cccf7fd882f1cc12b (1.37 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Efeswee.Properties.Resources.resources
Ypuevahf
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙