Suspicious
Suspect

cb4a5ce658739a3a304dabe560573b1b

PE Executable
|
MD5: cb4a5ce658739a3a304dabe560573b1b
|
Size: 931.84 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
cb4a5ce658739a3a304dabe560573b1b
Sha1
3ef7e0fcfb47096f2b57b8685c42aa1b476f3404
Sha256
003fd98ee31461ab7ec424f8180d4e18d9fb99927ec283f5940caa78bf0f5fac
Sha384
c0304fe2ab1fdfbd6c255adce7f05f06fec6551110878bd5de59440bfd2fe6a723978561302ef15e4e51900815b38d2b
Sha512
0f4f7ac268901b3a04fbb6556680425d8e520dc3a217cedf88760142980561a18ff69f12b9f3b8ceebc17a5fd2db203a6375d0c97240d6acd6542b8aa6b38890
SSDeep
24576:NrlBfc6Vj1Z0G7GzHhwgH8nmfMoop517nXkQ8vkZT7o2:9lB7tv7Ummf8p517nXX8vIo2
TLSH
5C15F1E43B71B719CE654A30EA79DEB642E61D7CB0017AE669DC7B17349C210AE0CF06

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PegSolitaire.StartMenuFormular.resources
PegSolitaire.Properties.Resources.resources
V6
[NBF]root.Data
mBLj
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: siPv.pdb

Module Name

siPv.exe

Full Name

siPv.exe

EntryPoint

System.Void PegSolitaire.Program::Main()

Scope Name

siPv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

siPv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

117

Main Method

System.Void PegSolitaire.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PegSolitaire.StartMenuFormular::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

siPv.exe

Full Name

siPv.exe

EntryPoint

System.Void PegSolitaire.Program::Main()

Scope Name

siPv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

siPv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

117

Main Method

System.Void PegSolitaire.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PegSolitaire.StartMenuFormular::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

cb4a5ce658739a3a304dabe560573b1b (931.84 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙