Suspicious
Suspect

d1a6ab98009518595867b6a4c106f268

PE Executable
|
MD5: d1a6ab98009518595867b6a4c106f268
|
Size: 1.31 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
d1a6ab98009518595867b6a4c106f268
Sha1
e897170e95606ed06e9a2ff3fd593643facfd138
Sha256
2f4de4bd0ba8bff96a2b2f8fe3703d0bea4dac48f6442cbd75677b3da8a4bb4f
Sha384
3d739d3ddd6bac87c9f62300f3cee08b1f99f12653adcff7d9f0167acd1c5e30ad24a20c6d5fe43ca983c3499853764f
Sha512
7a583dd15149dd7028f1fe8fb68fa7b613d0546eccbbfdfe7aef08b6a451663c71989ef8583dc2cbc8ed250bb0e83bfe4ee7d52e2be7de776af5b31113081c5f
SSDeep
24576:4dZZzdCJvkYzllNkPbdb9tV2CCuUMQziTSC2Q6RE:4vZzdizzjepb96LuUMdcN
TLSH
D855F12917E94A14F0FF5B38B77800680BF0BC2B9A31E66E6A5651DD0E61F49ED21373

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
7waLxJ5q2ae.g.resources
7waLxJ5q2ae.Resources.resources
46f56d277d3ef6.Resources.resources
2a8255e80
[NBF]root.Data
2a8255e81
[NBF]root.Data
2a8255e810
[NBF]root.Data
2a8255e811
[NBF]root.Data
2a8255e812
[NBF]root.Data
2a8255e813
[NBF]root.Data
2a8255e814
[NBF]root.Data
2a8255e815
[NBF]root.Data
2a8255e816
[NBF]root.Data
2a8255e817
[NBF]root.Data
2a8255e818
[NBF]root.Data
2a8255e819
[NBF]root.Data
2a8255e82
[NBF]root.Data
2a8255e820
[NBF]root.Data
2a8255e821
[NBF]root.Data
2a8255e822
[NBF]root.Data
2a8255e823
[NBF]root.Data
2a8255e824
[NBF]root.Data
2a8255e825
[NBF]root.Data
2a8255e826
[NBF]root.Data
2a8255e827
[NBF]root.Data
2a8255e828
[NBF]root.Data
2a8255e829
[NBF]root.Data
2a8255e83
[NBF]root.Data
2a8255e830
[NBF]root.Data
2a8255e831
[NBF]root.Data
2a8255e832
[NBF]root.Data
2a8255e833
[NBF]root.Data
2a8255e834
[NBF]root.Data
2a8255e835
[NBF]root.Data
2a8255e836
[NBF]root.Data
2a8255e837
[NBF]root.Data
2a8255e84
[NBF]root.Data
2a8255e85
[NBF]root.Data
2a8255e86
[NBF]root.Data
2a8255e87
[NBF]root.Data
2a8255e88
[NBF]root.Data
2a8255e89
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

7waLxJ5q2ae

Full Name

7waLxJ5q2ae

EntryPoint

System.Void 7waLxJ5q2ae.0naYCm3pkkN57/qAq1W.km5LwKq7R::sFz9H3wf()

Scope Name

7waLxJ5q2ae

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7waLxJ5q2ae

Assembly Version

22.20.3.288

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void 7waLxJ5q2ae.0naYCm3pkkN57/qAq1W.km5LwKq7R::sFz9H3wf()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 7waLxJ5q2ae.tLe7bq::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

7waLxJ5q2ae

Full Name

7waLxJ5q2ae

EntryPoint

System.Void 7waLxJ5q2ae.0naYCm3pkkN57/qAq1W.km5LwKq7R::sFz9H3wf()

Scope Name

7waLxJ5q2ae

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7waLxJ5q2ae

Assembly Version

22.20.3.288

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void 7waLxJ5q2ae.0naYCm3pkkN57/qAq1W.km5LwKq7R::sFz9H3wf()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 7waLxJ5q2ae.tLe7bq::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

d1a6ab98009518595867b6a4c106f268 (1.31 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙