Suspicious
Suspect

bd055d798c629634e3997cde00a2e540

PE Executable
|
MD5: bd055d798c629634e3997cde00a2e540
|
Size: 1.18 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
bd055d798c629634e3997cde00a2e540
Sha1
9ae631441fa2559ab553a62900a46556b2c4fde8
Sha256
8cd56ddaedb0cc45a957765ea3e590005a6fd09715308bf007aa24a2e0c15799
Sha384
d2669256c59251532a40bdfd561619d222b6e5ef6c303678827fe79c7d188ae3598fc14c4db44ec8d76ccc2dec6336c2
Sha512
2acbf9e8ce8ca973aea6013102c454f569b7fa1f0b3050da92f2f2dca08489f06bedf462347bb03a7d1ad34c104498ab1a07528a56262cdc65e3093461e5a559
SSDeep
24576:DSnA9hjSVhAezVMGwUuTzhCFGotQJeHQFDP9q7++ZD8hgDl6mZCfV7Dnau1491:l/SYMGUuqGoWJoMP9+jZDQgDlxZofnaR
TLSH
304512610319E713D1A607F22D94E3B8277A2F9CBA61E31A4DE92CEB7C353453A60357
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RESTAURANT_ORDER_SYSTEM.frm_restaurant.resources
$this.Icon
[NBF]root.IconData
gap
[NBF]root.Data
menuStrip1.TrayLocation
RESTAURANT_ORDER_SYSTEM.FrmNewProduct.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmNewTable.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmUpdatePrice.resources
RESTAURANT_ORDER_SYSTEM.Properties.Resources.resources
ksHc
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\KinbnsoioK\src\obj\Debug\ZPAT.pdb

Module Name

ZPAT.exe

Full Name

ZPAT.exe

EntryPoint

System.Void RESTAURANT_ORDER_SYSTEM.Program::Main()

Scope Name

ZPAT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ZPAT

Assembly Version

4.6.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

231

Main Method

System.Void RESTAURANT_ORDER_SYSTEM.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void RESTAURANT_ORDER_SYSTEM.frm_restaurant::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

bd055d798c629634e3997cde00a2e540 (1.18 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RESTAURANT_ORDER_SYSTEM.frm_restaurant.resources
$this.Icon
[NBF]root.IconData
gap
[NBF]root.Data
menuStrip1.TrayLocation
RESTAURANT_ORDER_SYSTEM.FrmNewProduct.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmNewTable.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmUpdatePrice.resources
RESTAURANT_ORDER_SYSTEM.Properties.Resources.resources
ksHc
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙