Suspicious
Suspect

c0e8b952d48131029fc522b33856dd38

PE Executable
|
MD5: c0e8b952d48131029fc522b33856dd38
|
Size: 1.05 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
c0e8b952d48131029fc522b33856dd38
Sha1
2379540ef40bd5bdd30375786715eb0ca8e10256
Sha256
49c288bdd977b430764c2067d4e25cb45dbbfb55105a080458af03221e776f63
Sha384
3091a46ecdcbaf5dfaeddfdc087596dfd35ffb1f7b197bafdb40540e448c08d997a75590f600aaaaea672301264b5351
Sha512
b2a2a64b9dd75308281313d5cc62b250e82950f9ee9856f0aeb5c600f2edd191d8eb819a929afb81fdc2a1d1918665e5404f0cfb094408c387e5b4d9d3199bda
SSDeep
24576:BrffG8hq8v2T/XBi69AZmZjaNCvJaRO6AymAVHe/:BtVvOnAYiAaRAymgHe
TLSH
34251160765ADD13D4798AF96032E3B543B26E5DE426C3CA9DC9FCE778F6B002850683

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Dorixona.Bimor.resources
Dorixona.Dorixona.resources
Dorixona.Firma.resources
Dorixona.Form1.resources
$this.Icon
[NBF]root.IconData
Dorixona.Properties.Resources.resources
DZoF
[NBF]root.Data
[NBF]root.Data-preview.png
nd
[NBF]root.Data
Informations
Name
Value
Module Name

XtcS.exe

Full Name

XtcS.exe

EntryPoint

System.Void Dorixona.Program::Main()

Scope Name

XtcS.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XtcS

Assembly Version

4.0.0.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

473

Main Method

System.Void Dorixona.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Dorixona.Login::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

XtcS.exe

Full Name

XtcS.exe

EntryPoint

System.Void Dorixona.Program::Main()

Scope Name

XtcS.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XtcS

Assembly Version

4.0.0.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

473

Main Method

System.Void Dorixona.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Dorixona.Login::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Artefacts
Name
Value
PDB Path

XtcS.pdb

c0e8b952d48131029fc522b33856dd38 (1.05 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Dorixona.Bimor.resources
Dorixona.Dorixona.resources
Dorixona.Firma.resources
Dorixona.Form1.resources
$this.Icon
[NBF]root.IconData
Dorixona.Properties.Resources.resources
DZoF
[NBF]root.Data
[NBF]root.Data-preview.png
nd
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

XtcS.pdb

c0e8b952d48131029fc522b33856dd38

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙