Suspicious
Suspect

bbb4c3e75cecca60b22f563c5db360c0

PE Executable
|
MD5: bbb4c3e75cecca60b22f563c5db360c0
|
Size: 560.64 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
bbb4c3e75cecca60b22f563c5db360c0
Sha1
294888d3be5e2490feaccbe12bcfa5bebde3a29b
Sha256
00459b7594c1c8c06f716c52eeaaa731181dabdff9a009c11a53cab010ac7748
Sha384
4b22a0073b2485fa11c3c9016a080c6c38b73eab92e073d8baa37bc3fcf9573f30285587ebc80a7bb586538697ef3894
Sha512
cdec3ee6837635ec2172ea2a069ce9e10b55bb3de4cb1a3d0db3ecd1159e0e86959893806890b5766b723e63c16cbb4193b26eae83146581881c9bb283196e6b
SSDeep
12288:3DK5wxdaMgJ3NhfXUwgPdwm903Zy4gZkIuqPy1:7XY3jXiwmO3jJIVy
TLSH
FDC401482659CF03C8775FF81961E1B023B9AE9DE922D60B9FD62CDFB879B405900793

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DicePoker.Forms.FormPrincipal.resources
DicePoker.Properties.Resources.resources
JhUNL
[NBF]root.Data
[NBF]root.Data-preview.png
VY
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: RcnBz.pdb

Module Name

RcnBz.exe

Full Name

RcnBz.exe

EntryPoint

System.Void DicePoker.Program::Main()

Scope Name

RcnBz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

RcnBz

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

335

Main Method

System.Void DicePoker.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DicePoker.Forms.FormPrincipal::.ctor() stloc.0 <null> ldloc.0 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

RcnBz.exe

Full Name

RcnBz.exe

EntryPoint

System.Void DicePoker.Program::Main()

Scope Name

RcnBz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

RcnBz

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

335

Main Method

System.Void DicePoker.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void DicePoker.Forms.FormPrincipal::.ctor() stloc.0 <null> ldloc.0 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

bbb4c3e75cecca60b22f563c5db360c0 (560.64 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DicePoker.Forms.FormPrincipal.resources
DicePoker.Properties.Resources.resources
JhUNL
[NBF]root.Data
[NBF]root.Data-preview.png
VY
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙