Suspicious
Suspect

c4b8b3069fc6d6001ebb213a1c37eb0b

PE Executable
|
MD5: c4b8b3069fc6d6001ebb213a1c37eb0b
|
Size: 1.3 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
c4b8b3069fc6d6001ebb213a1c37eb0b
Sha1
b21052e342fcd20e0838ad364fad93228a81c565
Sha256
32573f4e04f0b44e5affbf056876a1775e7a17700bfaca2192bace2558803b91
Sha384
d0b2128ad9808d2d77d6995d2e57af0f9f2ff731b698e3e7c4d3455e8378caec9cf22ee22f181675dd5f9cec37e98160
Sha512
743c4da594a81d623993a96dadcee152cefb865b23e84c17844bbf9802fd8576a7fbbf6f9081489edf3ad54656f11fcc29faafa559268731daba68156ca2161b
SSDeep
24576:hlnTF/fb39Z1JXJ0hvum/e29k7dtUmqth1KOb5pmvTI:hhTBfb9ZnXYv/ec4fizMvTI
TLSH
B255F10A0BD45AA4F0BECB74A7B4046443F0F517D32AEBAE798841F98E21B86D547773

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
eq5QmTi6.g.resources
eq5QmTi6.Resources.resources
0b14e1bb155447.Resources.resources
cd5ae02d0
[NBF]root.Data
cd5ae02d1
[NBF]root.Data
cd5ae02d10
[NBF]root.Data
cd5ae02d11
[NBF]root.Data
cd5ae02d12
[NBF]root.Data
cd5ae02d13
[NBF]root.Data
cd5ae02d14
[NBF]root.Data
cd5ae02d15
[NBF]root.Data
cd5ae02d16
[NBF]root.Data
cd5ae02d17
[NBF]root.Data
cd5ae02d18
[NBF]root.Data
cd5ae02d19
[NBF]root.Data
cd5ae02d2
[NBF]root.Data
cd5ae02d20
[NBF]root.Data
cd5ae02d21
[NBF]root.Data
cd5ae02d22
[NBF]root.Data
cd5ae02d23
[NBF]root.Data
cd5ae02d24
[NBF]root.Data
cd5ae02d25
[NBF]root.Data
cd5ae02d26
[NBF]root.Data
cd5ae02d27
[NBF]root.Data
cd5ae02d28
[NBF]root.Data
cd5ae02d29
[NBF]root.Data
cd5ae02d3
[NBF]root.Data
cd5ae02d30
[NBF]root.Data
cd5ae02d31
[NBF]root.Data
cd5ae02d32
[NBF]root.Data
cd5ae02d33
[NBF]root.Data
cd5ae02d34
[NBF]root.Data
cd5ae02d35
[NBF]root.Data
cd5ae02d36
[NBF]root.Data
cd5ae02d37
[NBF]root.Data
cd5ae02d38
[NBF]root.Data
cd5ae02d4
[NBF]root.Data
cd5ae02d5
[NBF]root.Data
cd5ae02d6
[NBF]root.Data
cd5ae02d7
[NBF]root.Data
cd5ae02d8
[NBF]root.Data
cd5ae02d9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

eq5QmTi6

Full Name

eq5QmTi6

EntryPoint

System.Void eq5QmTi6.mc3E8q/4AfjCn3dorN.2PdeXmg5sa0::5xsGfSw13kZkA0()

Scope Name

eq5QmTi6

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eq5QmTi6

Assembly Version

1.12.16.213

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void eq5QmTi6.mc3E8q/4AfjCn3dorN.2PdeXmg5sa0::5xsGfSw13kZkA0()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void eq5QmTi6.1xwFBj2::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

eq5QmTi6

Full Name

eq5QmTi6

EntryPoint

System.Void eq5QmTi6.mc3E8q/4AfjCn3dorN.2PdeXmg5sa0::5xsGfSw13kZkA0()

Scope Name

eq5QmTi6

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eq5QmTi6

Assembly Version

1.12.16.213

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void eq5QmTi6.mc3E8q/4AfjCn3dorN.2PdeXmg5sa0::5xsGfSw13kZkA0()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void eq5QmTi6.1xwFBj2::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

c4b8b3069fc6d6001ebb213a1c37eb0b (1.3 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙