Suspicious
Suspect

c21f86ac794dcd6e3b03c5e41e6b6cd1

PE Executable
|
MD5: c21f86ac794dcd6e3b03c5e41e6b6cd1
|
Size: 761.86 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
c21f86ac794dcd6e3b03c5e41e6b6cd1
Sha1
aa35f7241b5518223cbb5ba8f33e735833725e1e
Sha256
bfe8597cf704cb576063e7883146c8af4f384521ddc1ecb059d91d58480bc265
Sha384
4b1b75192929e862d0f0b68fd445a682cdc248fbeb0b66b915f072f8397c3d92e6e38cdbc65f269dbcc7bdc05710d944
Sha512
71dc10c0eef63fece77c223abf1e04a483c0b76de3b641332d686cf0aaeb70040cbeaa6574111c83ae76a35bf6ef8b4156d88d688cb0ac68a96e492e723523e1
SSDeep
12288:yPdiov8xzHu94dzCFnaDRUiiNoIrC1lwiUGjW/6pwf/+06Ldfz+Pv+igh8kovga2:yPdioEYmGFziimIrONjW/Dfm06lyOFqM
TLSH
1BF412107569D917DAF752F408B2F23083BB6EAE7412D3D18EEDAE9B74E9B101510A83

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Countdown_App.appForm.resources
$this.Icon
[NBF]root.IconData
Num
[NBF]root.Data
errorProvider1.TrayLocation
timer1.TrayLocation
Countdown_App.Properties.Resources.resources
_22
[NBF]root.Data
[NBF]root.Data-preview.png
_23
[NBF]root.Data
[NBF]root.Data-preview.png
mXocD
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\CAonDrEVlw\src\obj\Debug\Wvfwf.pdb

Module Name

Wvfwf.exe

Full Name

Wvfwf.exe

EntryPoint

System.Void Countdown_App.Program::Main()

Scope Name

Wvfwf.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Wvfwf

Assembly Version

4.2.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

257

Main Method

System.Void Countdown_App.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Countdown_App.appForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

Wvfwf.exe

Full Name

Wvfwf.exe

EntryPoint

System.Void Countdown_App.Program::Main()

Scope Name

Wvfwf.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Wvfwf

Assembly Version

4.2.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

257

Main Method

System.Void Countdown_App.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Countdown_App.appForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

c21f86ac794dcd6e3b03c5e41e6b6cd1 (761.86 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙