Suspicious
Suspect

b5c64be29a6e67322130007d596c264c

PE Executable
|
MD5: b5c64be29a6e67322130007d596c264c
|
Size: 745.47 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
b5c64be29a6e67322130007d596c264c
Sha1
c3b9c7c98441e790b581bb0a431e08ce12001775
Sha256
45da2c06168b05d8b841a107f57566701426ee5923785c922d6c52f18e019437
Sha384
c36373c55920069579fc9715caf4fcf9534a2087f85b824243a06a9c9fdfed81b2b7e099b23304b97bc21fe87683be79
Sha512
b3bac3ee55de73c5981f2beeb161f50b5f4c47d54e2459ee9eb7a1cabd726bd18c873d42ffa7da6e52ad8379c5d93f0ac2871d23995b40d6a2130669b733d94d
SSDeep
12288:AKqOZQ8VJOgVnGrgzrrZAlbovsmPIRS99yht5BlUQztFDT9E0JMPAt:vRQGZnHzc0vp9yjl9FDTJ5
TLSH
42F4F1042269CB02E1768FF01A31D2B40BB87EDAE921D3079EC53EDF7976B949945383

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
iWxN
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: XnNv.pdb

Module Name

XnNv.exe

Full Name

XnNv.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

XnNv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XnNv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

27

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_0045: ret stloc.0 <null> nop <null> ldstr An unexpected error occurred: ldloc.0 <null> callvirt System.String System.Exception::get_Message() ldstr The application will now close. call System.String System.String::Concat(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> nop <null> leave.s IL_0045: ret ret <null>

Module Name

XnNv.exe

Full Name

XnNv.exe

EntryPoint

System.Void EventLogAnalyzer.Program::Main()

Scope Name

XnNv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XnNv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

341

Main Method

System.Void EventLogAnalyzer.Program::Main()

Main IL Instruction Count

27

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> nop <null> newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_0045: ret stloc.0 <null> nop <null> ldstr An unexpected error occurred: ldloc.0 <null> callvirt System.String System.Exception::get_Message() ldstr The application will now close. call System.String System.String::Concat(System.String,System.String,System.String) ldstr Critical Error ldc.i4.0 <null> ldc.i4.s 16 call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon) pop <null> nop <null> leave.s IL_0045: ret ret <null>

b5c64be29a6e67322130007d596c264c (745.47 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙