Suspicious
Suspect

b4468307436f3490f2a22e2ce8ec8ae1

PE Executable
|
MD5: b4468307436f3490f2a22e2ce8ec8ae1
|
Size: 1.15 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
b4468307436f3490f2a22e2ce8ec8ae1
Sha1
471b20f6bd9df33504d5b7c33c39359bb607b5b9
Sha256
85cffbf528025f8a8af7935e9e1ef285a9da23cb8f454b78143ab2960d339a15
Sha384
cf07b2f2d0dc635acc22ba959d7964c94d4b675e721859bac9c1885a6ec043e1100908353e092d8bdf84935913fd7502
Sha512
6d6020d118e673b7fb19ef2a26e6d009f6ef73355f12c172a62e659b144a6bba4e988e861f3f29c4acbca1f9fefc9962007cf1972ff6e1935693cc9d71f1b89c
SSDeep
24576:yo6LKbAKqixsngVniJhOT+d/lLov/TI5aO:yo+KFCg0OStEv8U
TLSH
6635F16426A6CC17C379433219A0F27897B1CD97A111D24ABEED3DDB7B6AF150A83343

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
uf.RR.resources
OLk.JLC.resources
$this.Icon
[NBF]root.IconData
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancel.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bLP.wLH.resources
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnFind.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnList.Image
[NBF]root.Data
[NBF]root.Data-preview.png
hEp.oEo.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExit.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlue.Image
[NBF]root.Data
[NBF]root.Data-preview.png
cwq.zws.resources
btnChangePassword.Image
[NBF]root.Data
[NBF]root.Data-preview.png
twG.pwY.resources
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
L3c.w3n.resources
btnCalculatePrice.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Otopark.csdl
Otopark.msl
Otopark.ssdl
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
智慧停车管理专业版.Properties.Resources.resources
RHz
[NBF]root.Data
[NBF]root.Data-preview.png
Seren
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: gqN.pdb

Module Name

gqN.exe

Full Name

gqN.exe

EntryPoint

System.Void mgP.SgH::egS()

Scope Name

gqN.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gqN

Assembly Version

9.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

447

Main Method

System.Void mgP.SgH::egS()

Main IL Instruction Count

12

Main IL

br IL_0010: call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_001A: call System.Void zWV.yWM::jib() call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0005: ldc.i4.0 call System.Void zWV.yWM::jib() br IL_0024: newobj System.Void hEp.oEo::.ctor() newobj System.Void hEp.oEo::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0033: ret ret <null>

Module Name

gqN.exe

Full Name

gqN.exe

EntryPoint

System.Void mgP.SgH::egS()

Scope Name

gqN.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gqN

Assembly Version

9.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

447

Main Method

System.Void mgP.SgH::egS()

Main IL Instruction Count

12

Main IL

br IL_0010: call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) br IL_001A: call System.Void zWV.yWM::jib() call System.Void System.Windows.Forms.Application::EnableVisualStyles() br IL_0005: ldc.i4.0 call System.Void zWV.yWM::jib() br IL_0024: newobj System.Void hEp.oEo::.ctor() newobj System.Void hEp.oEo::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) br IL_0033: ret ret <null>

b4468307436f3490f2a22e2ce8ec8ae1 (1.15 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
uf.RR.resources
OLk.JLC.resources
$this.Icon
[NBF]root.IconData
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancel.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bLP.wLH.resources
btnSave.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnFind.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnList.Image
[NBF]root.Data
[NBF]root.Data-preview.png
hEp.oEo.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExit.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pctrBoxBlue.Image
[NBF]root.Data
[NBF]root.Data-preview.png
cwq.zws.resources
btnChangePassword.Image
[NBF]root.Data
[NBF]root.Data-preview.png
twG.pwY.resources
btnBack.Image
[NBF]root.Data
[NBF]root.Data-preview.png
L3c.w3n.resources
btnCalculatePrice.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Otopark.csdl
Otopark.msl
Otopark.ssdl
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
智慧停车管理专业版.Properties.Resources.resources
RHz
[NBF]root.Data
[NBF]root.Data-preview.png
Seren
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙