Suspicious
Suspect

ced3a2114df1ff503e14cbc0a2eacb13

PE Executable
|
MD5: ced3a2114df1ff503e14cbc0a2eacb13
|
Size: 1.12 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
ced3a2114df1ff503e14cbc0a2eacb13
Sha1
c99d22d9d6fb3fd4f02e286fdb25115f37833150
Sha256
425bdcae8624fd13ca4d75eeb557e781bb96d329856d5d5dca13b619756950de
Sha384
d0069b615ba70db587b9ac79a5e5bfe68aab98eb795bf071cf748572a638f90b883e7d3eb72e950fd34e1b30308d2c2c
Sha512
cb8d165b1c5676cc0ce665167d495a75641d3f6e04a91cd2d564650d12a710c0ec806ead1362b087c12a57f3405c51706fd3f8e6152fe1dafff149883f80a438
SSDeep
12288:bQqZBJ5nnpLBBJyMGQYMdH6oxpRAWFo6OBmBaWh2MUNoZVr6crHO2LQweMLA/YVj:bQYyMXYoa0boF+5ZhpIyCv9QT
TLSH
8F35B6342AEAA109F17BBF745BE074969ABFBEA33F03905D145423C64723940DEE153A

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ada uo.Pharmigol.resources
Ada uo.ShippingList_Menu.resources
MatrixLogo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
e9314e73ccad57.Resources.resources
8e811df00
[NBF]root.Data
8e811df01
[NBF]root.Data
8e811df010
[NBF]root.Data
8e811df011
[NBF]root.Data
8e811df012
[NBF]root.Data
8e811df013
[NBF]root.Data
8e811df02
[NBF]root.Data
8e811df03
[NBF]root.Data
8e811df04
[NBF]root.Data
8e811df05
[NBF]root.Data
8e811df06
[NBF]root.Data
8e811df07
[NBF]root.Data
8e811df08
[NBF]root.Data
8e811df09
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Ada uo

Full Name

Ada uo

EntryPoint

System.Void Ea03Do.Yc6k0S::t5ZAk4()

Scope Name

Ada uo

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ada uo

Assembly Version

2.9.1.4

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

3273

Main Method

System.Void Ea03Do.Yc6k0S::t5ZAk4()

Main IL Instruction Count

18

Main IL

nop <null> nop <null> newobj System.Void Ea03Do.Yc6k0S::.ctor() stloc.0 <null> ldloc.0 <null> callvirt System.Windows.Forms.RichTextBox Ea03Do.Yc6k0S::p1HWc4() callvirt System.String System.Windows.Forms.RichTextBox::get_Text() call System.Void Ea03Do.c1BS::Hx96(System.String) nop <null> leave.s IL_002A: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.1 <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_002A: nop nop <null> ret <null>

Module Name

Ada uo

Full Name

Ada uo

EntryPoint

System.Void Ea03Do.Yc6k0S::t5ZAk4()

Scope Name

Ada uo

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ada uo

Assembly Version

2.9.1.4

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

3273

Main Method

System.Void Ea03Do.Yc6k0S::t5ZAk4()

Main IL Instruction Count

18

Main IL

nop <null> nop <null> newobj System.Void Ea03Do.Yc6k0S::.ctor() stloc.0 <null> ldloc.0 <null> callvirt System.Windows.Forms.RichTextBox Ea03Do.Yc6k0S::p1HWc4() callvirt System.String System.Windows.Forms.RichTextBox::get_Text() call System.Void Ea03Do.c1BS::Hx96(System.String) nop <null> leave.s IL_002A: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.1 <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_002A: nop nop <null> ret <null>

ced3a2114df1ff503e14cbc0a2eacb13 (1.12 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ada uo.Pharmigol.resources
Ada uo.ShippingList_Menu.resources
MatrixLogo.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
e9314e73ccad57.Resources.resources
8e811df00
[NBF]root.Data
8e811df01
[NBF]root.Data
8e811df010
[NBF]root.Data
8e811df011
[NBF]root.Data
8e811df012
[NBF]root.Data
8e811df013
[NBF]root.Data
8e811df02
[NBF]root.Data
8e811df03
[NBF]root.Data
8e811df04
[NBF]root.Data
8e811df05
[NBF]root.Data
8e811df06
[NBF]root.Data
8e811df07
[NBF]root.Data
8e811df08
[NBF]root.Data
8e811df09
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙