Suspicious
Suspect

d5f5a4f90dc57b35c9fd9e653b9063ba

PE Executable
|
MD5: d5f5a4f90dc57b35c9fd9e653b9063ba
|
Size: 779.26 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
d5f5a4f90dc57b35c9fd9e653b9063ba
Sha1
7e1a60411fbf2edf313fd7482ae87159d808f74f
Sha256
79735be3c8426addcde6d4ed23d66cf6afd56f5aee015d806342fbf47259b55e
Sha384
13a44b1dd8e792cba015ce6dd5d6c7347a936f1a8983a591fe751544773ac115f4a57058354d0471af4526f2f2501779
Sha512
a74183b31cb891db47bd6bcb88e51298796bb6132a823d1a1749ddc9c89d34d92191a4cfca723b29cbb7961440911b8ed3bbbb78ccc9c184ff10cea6352a86f7
SSDeep
12288:oFM0S3saOFiTnKnqOKVVc+0dExo3OimrDrQem2D0eAx1R1KDz:lLOsT8eVVc+iEx66nQ0IeVD
TLSH
68F4128DFAA99F73C29C07B390875499D6E38497E137F2128EC59CB25D58A84C00BF97

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

gThr.exe

Full Name

gThr.exe

EntryPoint

System.Void SpeedType.Program::Main()

Scope Name

gThr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gThr

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void SpeedType.Program::Main()

Main IL Instruction Count

39

Main IL

ldsfld System.Int32[] SpeedType.FormResultados::Ⴅ stloc.2 <null> ldc.i4.2 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void SpeedType.Program::Ⴓ() ldc.i4 184 ldc.i4 195 call System.Void SpeedType.FormJuego::Ⴍ(System.Int32,System.Int16) ldc.i4.0 <null> ldc.i4.s 65 ldc.i4.s 77 call System.Void SpeedType.FormEstadisticas::Ⴄ(System.Boolean,System.Int32,System.Char) ldloc.2 <null> ldc.i4.s 102 ldelem.i4 <null> ldc.i4 60543 ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 279 ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 279 ldelem.i4 <null> ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 360 ldelem.i4 <null> add <null> ldc.i4 249 and <null> stelem.i4 <null> sub <null> stloc.1 <null> br.s IL_0008: ldloc.1 newobj System.Void SpeedType.FormMenuPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void SpeedType.Program::Main() pop <null> ret <null>

Module Name

gThr.exe

Full Name

gThr.exe

EntryPoint

System.Void SpeedType.Program::Main()

Scope Name

gThr.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

gThr

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void SpeedType.Program::Main()

Main IL Instruction Count

39

Main IL

ldsfld System.Int32[] SpeedType.FormResultados::Ⴅ stloc.2 <null> ldc.i4.2 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void SpeedType.Program::Ⴓ() ldc.i4 184 ldc.i4 195 call System.Void SpeedType.FormJuego::Ⴍ(System.Int32,System.Int16) ldc.i4.0 <null> ldc.i4.s 65 ldc.i4.s 77 call System.Void SpeedType.FormEstadisticas::Ⴄ(System.Boolean,System.Int32,System.Char) ldloc.2 <null> ldc.i4.s 102 ldelem.i4 <null> ldc.i4 60543 ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 279 ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 279 ldelem.i4 <null> ldsfld System.Int32[] SpeedType.FormMenuPrincipal::Ⴐ ldc.i4 360 ldelem.i4 <null> add <null> ldc.i4 249 and <null> stelem.i4 <null> sub <null> stloc.1 <null> br.s IL_0008: ldloc.1 newobj System.Void SpeedType.FormMenuPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void SpeedType.Program::Main() pop <null> ret <null>

d5f5a4f90dc57b35c9fd9e653b9063ba (779.26 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙