Suspicious
Suspect

d355a13fb83919148c79de74b5862f38

PE Executable
|
MD5: d355a13fb83919148c79de74b5862f38
|
Size: 979.97 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
d355a13fb83919148c79de74b5862f38
Sha1
a6a6035f125d80d8c164d8067ede158d082dacbf
Sha256
ed17eb2e83fcca67ba66de21c6357ed58d2c684793aa0e7364e120c189488a6e
Sha384
83d99443f9342d0f8b1859fa00c79f49850c852e0cb855b418b77890f85500df50ee101cba023379004d57d89b65a718
Sha512
556276d4ea6d3ba906950d9aecc8795412d3dcdc510d431cf1c59079da64177da730e383ffa780fb8d0b073f6df9728e37bc177a7138560bb661a9ae264bd5b3
SSDeep
24576:iJz7mY4QJI+a9prM5pJwth/NUJi0FT9dM4efvvw:Az7X4QJe9WLQhifbTefw
TLSH
342522905103E806C5FB0BB448B5E7F9437D5E89BA04D317AAED3C8F3C1A656BC91396

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QuantumSimulator.Form1.resources
$this.Icon
[NBF]root.IconData
btnClientSocket.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
QuantumSimulator.op1.resources
QuantumSimulator.Properties.Resources.resources
fabrica02
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica03
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica04
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica05
[NBF]root.Data
[NBF]root.Data-preview.png
pKOU
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: xTik.pdb

Module Name

xTik.exe

Full Name

xTik.exe

EntryPoint

System.Void QuantumSimulator.Program::Main()

Scope Name

xTik.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xTik

Assembly Version

7.4.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

63

Main Method

System.Void QuantumSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void QuantumSimulator.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

xTik.exe

Full Name

xTik.exe

EntryPoint

System.Void QuantumSimulator.Program::Main()

Scope Name

xTik.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xTik

Assembly Version

7.4.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

63

Main Method

System.Void QuantumSimulator.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void QuantumSimulator.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

d355a13fb83919148c79de74b5862f38 (979.97 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙