Suspicious
Suspect

c9fd967cddffa06167760c9e236463ea

PE Executable
|
MD5: c9fd967cddffa06167760c9e236463ea
|
Size: 3.99 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
c9fd967cddffa06167760c9e236463ea
Sha1
4ba1935d39a1a0f7bb0e8533ed5e361d41369b6b
Sha256
27b4e7871c2374bcfae2fe960fd7fbdfebabc9ca84c2569c45e7438e0d356a78
Sha384
242fa930e76722e6d14d703a776a3a58be028fe4163a15416b2a516ef015a4ca56afd994d86c93147ee9294dacab2367
Sha512
bced07ce3a754537b10539f6bf4b2c9eaabcc6e3decf17b333c682ece2317952d75bafc9dc6e89c89b9b768b08d1bc0c2a01c3659a3624085df63976edccc28a
SSDeep
98304:AC+gs3iL85OeEmWV+cbwrV7IUWcC/tfrnDqIUVI3ixY3:AdtnORHzwqLcMtSFI3iO
TLSH
0C06336922428C52C5526FF80BB1D5B60E7DBFCCED51E34B0ECA3CEB712629859473A1

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PaintPlus.Properties.Resources.resources
VY
[NBF]root.Data
ajijJ
[NBF]root.Data
[NBF]root.Data-preview.png
image_39
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: DusQF.pdb

Module Name

DusQF.exe

Full Name

DusQF.exe

EntryPoint

System.Void PaintPlus.Program::Main()

Scope Name

DusQF.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

DusQF

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

128

Main Method

System.Void PaintPlus.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PaintPlus.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

DusQF.exe

Full Name

DusQF.exe

EntryPoint

System.Void PaintPlus.Program::Main()

Scope Name

DusQF.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

DusQF

Assembly Version

201.502.607.709

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

128

Main Method

System.Void PaintPlus.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PaintPlus.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

c9fd967cddffa06167760c9e236463ea (3.99 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PaintPlus.Properties.Resources.resources
VY
[NBF]root.Data
ajijJ
[NBF]root.Data
[NBF]root.Data-preview.png
image_39
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙