Suspicious
Suspect

b6352fbd12fece1f752420e01ddd60bd

PE Executable
|
MD5: b6352fbd12fece1f752420e01ddd60bd
|
Size: 753.66 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
b6352fbd12fece1f752420e01ddd60bd
Sha1
9e764ce6deaacbfa9db1188d05dee7dffe91ecbd
Sha256
371f1cb8f80e05125b0673ba6bcb23237cdfa3c66f2954561ee476b8d6f89e70
Sha384
2094060c5aaafd2ac460ebe8f79fcb742cae186b41e29273295e8400318f13df123830e618c776650c753bacecaaf2c6
Sha512
cb402158b526e65da13d618f2ecb504f881a082fe54ea8aa4b3b2d39027d51f2a5a62e26468a2c342faba9d6564e82e70c07847272cdeba6d0aa06fee07b9758
SSDeep
12288:VU1/3plPNyF4dkQXcY56ipwISPcBjMpHJJ+FY3hRjAU5+dkDrIYFb2c4q48WG7:OF5lPNIWkIcWpwRPcgpwchRDzD1fX4c7
TLSH
4CF40106A93ADD11C0A20B746B21EDB0137BAC4CB424D7179EEABDCBB73774115C1A9B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DamassaProject.fmrAdministrador.resources
DamassaProject.fmrListarUsuario.resources
$this.Icon
[NBF]root.IconData
MR
[NBF]root.Data
usuarioRepositoryBindingSource.TrayLocation
DamassaProject.fmrLogin.resources
pic_Imagem.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
pic_Logo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.fmrSplash.resources
pic_Image.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.Properties.Resources.resources
GpHe
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Module Name

cLTC.exe

Full Name

cLTC.exe

EntryPoint

System.Void DamassaProject.Program::Main()

Scope Name

cLTC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

cLTC

Assembly Version

1.3.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

230

Main Method

System.Void DamassaProject.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DamassaProject.fmrListarUsuario::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

cLTC.exe

Full Name

cLTC.exe

EntryPoint

System.Void DamassaProject.Program::Main()

Scope Name

cLTC.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

cLTC

Assembly Version

1.3.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

230

Main Method

System.Void DamassaProject.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DamassaProject.fmrListarUsuario::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
PDB Path

C:\Users\Administrator\Desktop\Client\Temp\UKkVjWWNam\src\obj\Debug\cLTC.pdb

Embedded Resources

7

Suspicious Type Names (1-2 chars)

0

b6352fbd12fece1f752420e01ddd60bd (753.66 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DamassaProject.fmrAdministrador.resources
DamassaProject.fmrListarUsuario.resources
$this.Icon
[NBF]root.IconData
MR
[NBF]root.Data
usuarioRepositoryBindingSource.TrayLocation
DamassaProject.fmrLogin.resources
pic_Imagem.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
pic_Logo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.fmrSplash.resources
pic_Image.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
DamassaProject.Properties.Resources.resources
GpHe
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

C:\Users\Administrator\Desktop\Client\Temp\UKkVjWWNam\src\obj\Debug\cLTC.pdb

b6352fbd12fece1f752420e01ddd60bd

Embedded Resources

7

b6352fbd12fece1f752420e01ddd60bd

Suspicious Type Names (1-2 chars)

0

b6352fbd12fece1f752420e01ddd60bd

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙