Suspicious
Suspect

cfb41c1d7dadbc843d62b686e65345c9

PE Executable
|
MD5: cfb41c1d7dadbc843d62b686e65345c9
|
Size: 1.18 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
cfb41c1d7dadbc843d62b686e65345c9
Sha1
c097afb3332e9facf37e2cbdd117cd0a0e36b2ab
Sha256
74227624a51478a2fafb8f24adc7eb69ff8f171defcdbdc865704b90928ec883
Sha384
01d51f07e222209081e958d3ea1f539ead7e654ab4cb398c5da2315371663aa19241d866e0cf1ef92c6d77a6399e9d3d
Sha512
761e57637e58a8c6350b24a0bba06fddcd50a1daded5259ca3a898ce605d20fbbeebe9fa8296bbe23084f9a99357fc4d7296ce21011f69551f86ade22b0e01a3
SSDeep
24576:xfphBLTmBjcIW9LZ0/5MIudbmh4w5eEAEl+:zbLTwoB9LZs53udecz
TLSH
7245BE413389DF11D16F1AB1C8B2C6F41767BE05EC11D3CB6AD9BE6B78B23A42941293

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
JNoG
[NBF]root.Data
[NBF]root.Data-preview.png
dr
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x11CC00 size 13832 bytes

Info

PDB Path: rnQU.pdb

Module Name

rnQU.exe

Full Name

rnQU.exe

EntryPoint

System.Void HTMLValidator.Program::Main()

Scope Name

rnQU.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

rnQU

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

364

Main Method

System.Void HTMLValidator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void HTMLValidator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

rnQU.exe

Full Name

rnQU.exe

EntryPoint

System.Void HTMLValidator.Program::Main()

Scope Name

rnQU.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

rnQU

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

364

Main Method

System.Void HTMLValidator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void HTMLValidator.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

cfb41c1d7dadbc843d62b686e65345c9 (1.18 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙