Suspicious
Suspect

baa80521acada137d15e7f6597b604f8

PE Executable
|
MD5: baa80521acada137d15e7f6597b604f8
|
Size: 4.09 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
baa80521acada137d15e7f6597b604f8
Sha1
d2c836f53856030ebbddcc7cb3b330830c8a2a08
Sha256
c9b1c0660b49eeaea761b489d5c00235f7a597b4a5b244643418d6375e436b42
Sha384
3512ed17ebb0a71fc34b0887dad12e9bc3930ed164068ca24f0339cc11cef1aae657f2c93df47259a72919077d642587
Sha512
5ce23552b8c41f285fd31c60c0b108fd27ded074194880b4e5ff43c6dc3c2d1cb6f19605006a6e54adc614179515d5657d953b56e72e1ee9cc1d71b50a94c805
SSDeep
98304:p6QrYAZY52zt3j7eCdymyjUVyJvaUr8HEOrxiO+Efw:p6kymtz7TVydpOdi1N
TLSH
F11623CC36503AEEC803CC705A641DA896476E677B0B32039D1B796BB63F8C79E554B2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
<iiM=
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

server1.exe

Full Name

server1.exe

EntryPoint

System.Void ‮‮‎‎‌‏‏‬‪‪​‏‭‌‬‪‫‭​‪‭‎‮‫‎‬‮::‬‌‬‬‏​‌‫‭‮‫‬‎​‎‮‫​‭​‮()

Scope Name

server1.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

server1

Assembly Version

1.6.8.9

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.8

Total Strings

1

Main Method

System.Void ‮‮‎‎‌‏‏‬‪‪​‏‭‌‬‪‫‭​‪‭‎‮‫‎‬‮::‬‌‬‬‏​‌‫‭‮‫‬‎​‎‮‫​‭​‮()

Main IL Instruction Count

0

Main IL

baa80521acada137d15e7f6597b604f8 (4.09 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
<iiM=
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙