Suspicious
Suspect

d045d15e4ec6f13511744fc467534ede

PE Executable
|
MD5: d045d15e4ec6f13511744fc467534ede
|
Size: 527.36 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
d045d15e4ec6f13511744fc467534ede
Sha1
f4b3589a15aadd4cd668bd4284b6b71edfe24795
Sha256
5df3d8015e5455e562f438a9540b8ed45d8fae27ac5ebd37cbd3074a60d09edb
Sha384
97d156cff76ff43a30d6e0e98b725ccb7bb8d245c1dadec21a34d6e0c1f77513b655bc1c221a8a904c04c42d05302ff9
Sha512
e179dfe2495405f4b6ecab9c8fb28d78df595317967970a70b3a9738d3d89d1381e7f5e70f75ef8d9ae4d30ea90cac186d6dbd77998c25f5ad6f5122b076d28d
SSDeep
12288:4oYYWHuSJMc8J24rYPq//iBCIsh4CMWWWF4wBh:XYYWOS2bOPq//sCICZMXWG8
TLSH
66B4DF5063A9AA02E5B65BF01C70D3740739BD5EBA32D20A5FE67CEF3836B409851793

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ErrorAnalyzer.Forms.MainForm.resources
ErrorAnalyzer.Properties.Resources.resources
Coloring
[NBF]root.Data
FEby
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: eKfP.pdb

Module Name

eKfP.exe

Full Name

eKfP.exe

EntryPoint

System.Void ErrorAnalyzer.Program::Main()

Scope Name

eKfP.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eKfP

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

438

Main Method

System.Void ErrorAnalyzer.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

eKfP.exe

Full Name

eKfP.exe

EntryPoint

System.Void ErrorAnalyzer.Program::Main()

Scope Name

eKfP.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eKfP

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

438

Main Method

System.Void ErrorAnalyzer.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

d045d15e4ec6f13511744fc467534ede (527.36 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙