Suspicious
Suspect

cf0481342e04e8f44eb8d0a340390554

PE Executable
|
MD5: cf0481342e04e8f44eb8d0a340390554
|
Size: 1.03 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
cf0481342e04e8f44eb8d0a340390554
Sha1
55ba354c6ae2b0e953344e0d13be4345405d6da2
Sha256
13824be7378d454cf0da9481048b1ad869e2bdbe05340a34792674debef6916a
Sha384
10b02b3324130cbffdc03513a8cdab3b1f777b35cf3db415714b4a7c1b7718a3e78d27fbc149ff2298b33a34000f0108
Sha512
ce2f0ce606bc43c2ed727dcb4dad36fe32aa1f6f2f669c994481bbc0aede83a9389032aa4e21515d6e723503933610579b4b9246d046095e884df2b590291315
SSDeep
24576:XerZnXqyllglglglvRsA9CcpMFpHZjD4pTgZVFQ:X86F4cpMFh4kZVF
TLSH
B225019E3395DE13D2A891F3C820F67083F51D9BB911C3C98DEA6CDB75E5B026241A93
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
ExwX
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\vhjzuURrim\src\obj\Debug\gYui.pdb

Module Name

gYui.exe

Full Name

gYui.exe

EntryPoint

System.Void IndexApp.Program::Main()

Scope Name

gYui.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gYui

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

749

Main Method

System.Void IndexApp.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void IndexApp.IndexApp::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

cf0481342e04e8f44eb8d0a340390554 (1.03 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙