Suspicious
Suspect

c9d7e227542e02fff35cb8b0ac7c2ea3

PE Executable
|
MD5: c9d7e227542e02fff35cb8b0ac7c2ea3
|
Size: 1.22 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
c9d7e227542e02fff35cb8b0ac7c2ea3
Sha1
1064732d10d051b260322ebbdae1fadcc3bb3be3
Sha256
14266e901e5083d9577b8268b0de5e22d34e04693931a7fc04cbe33ed09e0d2b
Sha384
41098ef88fbd435f2c415be8fb06269a7379b9cdcab5561f1ef0645a0a590d8fd193d860d6a139aad05e99989683a536
Sha512
e2e2ac70522aa8cdbbba3e263bf6910e6844604c5989e3b8e8775d492f463c8c490cd27c53d1e9b9fd44e13e30bd214ecee6af288de7a223a06b2fc1a204f4f0
SSDeep
24576:jPt9sgN5bY5fzpeKGgd3IWumRnJydICnngYlA6US+RmjjZnXl:jt95Ufz8Wd3vuwCnglRi
TLSH
DB45F14032A89D0BE1B64AF046B4E2B40BB47E59B5A5D6CF5DC17CCF39F6B814A42B13

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Assignment_2.ClassBooking.resources
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
memberBindingNavigatorSaveItem.Image
Assignment_2.MainMenu.resources
$this.Icon
[NBF]root.IconData
SHT
[NBF]root.Data
Assignment_2.Properties.Resources.resources
CityGymLogo
[NBF]root.Data
[NBF]root.Data-preview.png
ContactDetails
[NBF]root.Data
[NBF]root.Data-preview.png
Extras
[NBF]root.Data
[NBF]root.Data-preview.png
Help
[NBF]root.Data
[NBF]root.Data-preview.png
Membership Durationb
[NBF]root.Data
[NBF]root.Data-preview.png
Membership settings
[NBF]root.Data
[NBF]root.Data-preview.png
PaymentOptions
[NBF]root.Data
[NBF]root.Data-preview.png
PersonalGoals
[NBF]root.Data
[NBF]root.Data-preview.png
Special
[NBF]root.Data
[NBF]root.Data-preview.png
Start date
[NBF]root.Data
[NBF]root.Data-preview.png
TTxF
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\eKfKnavImU\src\obj\Debug\AryI.pdb

Module Name

AryI.exe

Full Name

AryI.exe

EntryPoint

System.Void Assignment_2.Program::Main()

Scope Name

AryI.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

AryI

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

1482

Main Method

System.Void Assignment_2.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Assignment_2.MainMenu::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

AryI.exe

Full Name

AryI.exe

EntryPoint

System.Void Assignment_2.Program::Main()

Scope Name

AryI.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

AryI

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

1482

Main Method

System.Void Assignment_2.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void Assignment_2.MainMenu::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

c9d7e227542e02fff35cb8b0ac7c2ea3 (1.22 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙