Suspicious
Suspect

b4036cd6df3486016e3981dae18cb244

PE Executable
|
MD5: b4036cd6df3486016e3981dae18cb244
|
Size: 1.35 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
b4036cd6df3486016e3981dae18cb244
Sha1
951688350922775b50afa157ace69962c2efb770
Sha256
b52ec88f039fc53ac5e08d94ba37afa36bc3456075eb61c1892f367e57ae91d7
Sha384
62d79cfe00582c1a7bc4ffcff14da004c6907b30db7c672eb699da6ccd13b8bca43d16034857a45fe2a8e71a5c8e5fe1
Sha512
f19594b33badf9ff2b4622ac22cdd7a78dafcebd8d04718b0ca1275bb20974697ab64770a408bb9aaccc64dc8a2f45a6fa679a307bb2f44b22abd05be12a6452
SSDeep
24576:3onTF/fb39Z1JXJ0ICnRveYepqMKDmfC4KOSSn2i61hi/ag:3uTBfb9ZnXSRveYkqM3fC41p2fo/ag
TLSH
9355F10617D446A4F0BF8B74BAB8046547F0F907D72AEBAE798840FD8D21B81D952773

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
st2Q1Cikyf3K4a.g.resources
st2Q1Cikyf3K4a.Resources.resources
9fb9f7182689e2.Resources.resources
769316cf0
[NBF]root.Data
769316cf1
[NBF]root.Data
769316cf10
[NBF]root.Data
769316cf11
[NBF]root.Data
769316cf12
[NBF]root.Data
769316cf13
[NBF]root.Data
769316cf14
[NBF]root.Data
769316cf15
[NBF]root.Data
769316cf16
[NBF]root.Data
769316cf17
[NBF]root.Data
769316cf18
[NBF]root.Data
769316cf19
[NBF]root.Data
769316cf2
[NBF]root.Data
769316cf20
[NBF]root.Data
769316cf21
[NBF]root.Data
769316cf22
[NBF]root.Data
769316cf23
[NBF]root.Data
769316cf24
[NBF]root.Data
769316cf25
[NBF]root.Data
769316cf26
[NBF]root.Data
769316cf27
[NBF]root.Data
769316cf28
[NBF]root.Data
769316cf29
[NBF]root.Data
769316cf3
[NBF]root.Data
769316cf30
[NBF]root.Data
769316cf31
[NBF]root.Data
769316cf32
[NBF]root.Data
769316cf33
[NBF]root.Data
769316cf34
[NBF]root.Data
769316cf35
[NBF]root.Data
769316cf36
[NBF]root.Data
769316cf37
[NBF]root.Data
769316cf38
[NBF]root.Data
769316cf39
[NBF]root.Data
769316cf4
[NBF]root.Data
769316cf40
[NBF]root.Data
769316cf41
[NBF]root.Data
769316cf5
[NBF]root.Data
769316cf6
[NBF]root.Data
769316cf7
[NBF]root.Data
769316cf8
[NBF]root.Data
769316cf9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

st2Q1Cikyf3K4a

Full Name

st2Q1Cikyf3K4a

EntryPoint

System.Void st2Q1Cikyf3K4a.tEe8if2S/cx1D4xBrec8A.nr3EN4ez8xm::gYe8w5()

Scope Name

st2Q1Cikyf3K4a

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

st2Q1Cikyf3K4a

Assembly Version

17.4.34.71

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void st2Q1Cikyf3K4a.tEe8if2S/cx1D4xBrec8A.nr3EN4ez8xm::gYe8w5()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void st2Q1Cikyf3K4a.3Qwdj::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

st2Q1Cikyf3K4a

Full Name

st2Q1Cikyf3K4a

EntryPoint

System.Void st2Q1Cikyf3K4a.tEe8if2S/cx1D4xBrec8A.nr3EN4ez8xm::gYe8w5()

Scope Name

st2Q1Cikyf3K4a

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

st2Q1Cikyf3K4a

Assembly Version

17.4.34.71

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void st2Q1Cikyf3K4a.tEe8if2S/cx1D4xBrec8A.nr3EN4ez8xm::gYe8w5()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void st2Q1Cikyf3K4a.3Qwdj::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

b4036cd6df3486016e3981dae18cb244 (1.35 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙