Suspicious
Suspect

b3e1780b8689a4eb78f60dc8df092d8d

PE Executable
|
MD5: b3e1780b8689a4eb78f60dc8df092d8d
|
Size: 1.99 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
b3e1780b8689a4eb78f60dc8df092d8d
Sha1
3261d73e9df352bf1999029013543302b4ad10a6
Sha256
6f0918d85cc9f27d09b3100b357e115a4cd35a492cc901f95d9a9cd07e1d4f9f
Sha384
a5e2435a8015cbdeadd0069fcef11c4602fc53025458f470a087a1365debff15873b640d354a2439c1b326a828b659d8
Sha512
7a7ccf6008ffac202f1a05c3f991ae6ddb1acc0a14b043d75d835bdc7d2e4776fb2efef468d00f9fd8cbe566fa13ad3bce295eced1abcda4936a6fe78f023410
SSDeep
12288:mu1eFuUja/FMmAdbG2Z8ZhgpsdC+VeDlOKi8LcspeDIzomMYB0:zFMmAd78vdC+UDlOzRmi
TLSH
1C95D83CEEC83236E5B7A67AC9F505CBBE517843365A5C0E449A03860D53F97BE8211E

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
et6BFwa3y_2YxS.ns2Q_5.resources
ffb13dd56af8f4.Resources.resources
9dc13a5f0
[NBF]root.Data
9dc13a5f1
[NBF]root.Data
9dc13a5f10
[NBF]root.Data
9dc13a5f11
[NBF]root.Data
9dc13a5f12
[NBF]root.Data
9dc13a5f13
[NBF]root.Data
9dc13a5f14
[NBF]root.Data
9dc13a5f15
[NBF]root.Data
9dc13a5f16
[NBF]root.Data
9dc13a5f17
[NBF]root.Data
9dc13a5f18
[NBF]root.Data
9dc13a5f19
[NBF]root.Data
9dc13a5f2
[NBF]root.Data
9dc13a5f20
[NBF]root.Data
9dc13a5f21
[NBF]root.Data
9dc13a5f22
[NBF]root.Data
9dc13a5f23
[NBF]root.Data
9dc13a5f24
[NBF]root.Data
9dc13a5f25
[NBF]root.Data
9dc13a5f3
[NBF]root.Data
9dc13a5f4
[NBF]root.Data
9dc13a5f5
[NBF]root.Data
9dc13a5f6
[NBF]root.Data
9dc13a5f7
[NBF]root.Data
9dc13a5f8
[NBF]root.Data
9dc13a5f9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

et6BFwa3y_2YxS

Full Name

et6BFwa3y_2YxS

EntryPoint

System.Void et6BFwa3y_2YxS.Neq7n5fE::7pxS_0Dn()

Scope Name

et6BFwa3y_2YxS

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

et6BFwa3y_2YxS

Assembly Version

6.22.15.207

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

2245

Main Method

System.Void et6BFwa3y_2YxS.Neq7n5fE::7pxS_0Dn()

Main IL Instruction Count

4

Main IL

nop <null> newobj System.Void et6BFwa3y_2YxS.5Wtzdr::.ctor() stloc.0 <null> ret <null>

Module Name

et6BFwa3y_2YxS

Full Name

et6BFwa3y_2YxS

EntryPoint

System.Void et6BFwa3y_2YxS.Neq7n5fE::7pxS_0Dn()

Scope Name

et6BFwa3y_2YxS

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

et6BFwa3y_2YxS

Assembly Version

6.22.15.207

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

2245

Main Method

System.Void et6BFwa3y_2YxS.Neq7n5fE::7pxS_0Dn()

Main IL Instruction Count

4

Main IL

nop <null> newobj System.Void et6BFwa3y_2YxS.5Wtzdr::.ctor() stloc.0 <null> ret <null>

b3e1780b8689a4eb78f60dc8df092d8d (1.99 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙