Suspicious
Suspect

d7d43ee523bc8379bcc07e49f0fc90fb

PE Executable
|
MD5: d7d43ee523bc8379bcc07e49f0fc90fb
|
Size: 1.3 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
d7d43ee523bc8379bcc07e49f0fc90fb
Sha1
86f8bf68e81d5e3fd34ae1d81ecc82cbbf121ba9
Sha256
f5746df1a4d266a2f7718fe251546dff7a8e3bbce8f766277df74f0145c69d11
Sha384
a7395f45ec865015f5dc993da65bd5db311597bff5b0441c145aa79a9193cc485f94126e1590064aaa369b0db1eef267
Sha512
7405614577a1e11a884109e12f17b1b25e479ed2973e0ee010defb5bd9ec1c6a0dbb20a496448dcc35902da70ed86fd47dddbf7d8dcd5a1b64bcf6ed744c2eb6
SSDeep
24576:EjnTF/fb39Z1JXJ0Nvum/e29k7dtUmqtV1KObrhLGb:ELTBfb9ZnXgv/ec4fm1hLGb
TLSH
A855E10A17D416A4F0BEDB74ABB5046443F0F51BD32AEBAF798841F98E21B869543373

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
7Hmaj1GyD.g.resources
7Hmaj1GyD.Resources.resources
f8bdcea4583a3b.Resources.resources
5124bdbd0
[NBF]root.Data
5124bdbd1
[NBF]root.Data
5124bdbd10
[NBF]root.Data
5124bdbd11
[NBF]root.Data
5124bdbd12
[NBF]root.Data
5124bdbd13
[NBF]root.Data
5124bdbd14
[NBF]root.Data
5124bdbd15
[NBF]root.Data
5124bdbd16
[NBF]root.Data
5124bdbd17
[NBF]root.Data
5124bdbd18
[NBF]root.Data
5124bdbd19
[NBF]root.Data
5124bdbd2
[NBF]root.Data
5124bdbd20
[NBF]root.Data
5124bdbd21
[NBF]root.Data
5124bdbd22
[NBF]root.Data
5124bdbd23
[NBF]root.Data
5124bdbd24
[NBF]root.Data
5124bdbd25
[NBF]root.Data
5124bdbd26
[NBF]root.Data
5124bdbd27
[NBF]root.Data
5124bdbd28
[NBF]root.Data
5124bdbd29
[NBF]root.Data
5124bdbd3
[NBF]root.Data
5124bdbd30
[NBF]root.Data
5124bdbd31
[NBF]root.Data
5124bdbd32
[NBF]root.Data
5124bdbd33
[NBF]root.Data
5124bdbd34
[NBF]root.Data
5124bdbd35
[NBF]root.Data
5124bdbd36
[NBF]root.Data
5124bdbd37
[NBF]root.Data
5124bdbd38
[NBF]root.Data
5124bdbd4
[NBF]root.Data
5124bdbd5
[NBF]root.Data
5124bdbd6
[NBF]root.Data
5124bdbd7
[NBF]root.Data
5124bdbd8
[NBF]root.Data
5124bdbd9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

7Hmaj1GyD

Full Name

7Hmaj1GyD

EntryPoint

System.Void 7Hmaj1GyD.Hp6jks/5Bzfr.Cpy7s3Mrs::cYy2T()

Scope Name

7Hmaj1GyD

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7Hmaj1GyD

Assembly Version

8.19.28.285

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void 7Hmaj1GyD.Hp6jks/5Bzfr.Cpy7s3Mrs::cYy2T()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 7Hmaj1GyD.Eq4_1::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

7Hmaj1GyD

Full Name

7Hmaj1GyD

EntryPoint

System.Void 7Hmaj1GyD.Hp6jks/5Bzfr.Cpy7s3Mrs::cYy2T()

Scope Name

7Hmaj1GyD

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7Hmaj1GyD

Assembly Version

8.19.28.285

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void 7Hmaj1GyD.Hp6jks/5Bzfr.Cpy7s3Mrs::cYy2T()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 7Hmaj1GyD.Eq4_1::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

d7d43ee523bc8379bcc07e49f0fc90fb (1.3 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙