Suspicious
Suspect

da48937212b76588c45690ad0952e04e

PE Executable
|
MD5: da48937212b76588c45690ad0952e04e
|
Size: 777.22 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
da48937212b76588c45690ad0952e04e
Sha1
f3f2c6d631c7b36e88e6c872655787995179610a
Sha256
196dc01366e21c79a4a494c686aa8ef45e1da36b338b7a85a0ff3295d008adc8
Sha384
fea3b8ea6f0b9d3ee7dbc39a6805db79bd26c899648984fe13e9acb6906a08028c24a98baa5b6d226a47f0bbb696855a
Sha512
2f366b40a035e6c6325447dc1b725116c0a80b95946fa674f33b5d283657375befb682a8245f5caeabe9e80742c47fd0472c391ed527b13c93e704c9ac263995
SSDeep
12288:sKLKSXhFHQGUppkaJnEXjP4GQy+OXQsAz8lj0OtdRVDLVFCrAxik+MSZf9i34r:3LKSRFHQtppOj/QeJAQlj0ebVDLPRikV
TLSH
28F423B1A228CBA3C8A177FA05B1E37593F80E1DD520E21B4EEDADFB7919B151590313

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScramble.FormMenuPrincipale.resources
WordScramble.Properties.Resources.resources
NH
[NBF]root.Data
TKx
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: JPh.pdb

Module Name

JPh.exe

Full Name

JPh.exe

EntryPoint

System.Void WordScramble.Program::Main()

Scope Name

JPh.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

JPh

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

238

Main Method

System.Void WordScramble.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WordScramble.FormMenuPrincipale::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

JPh.exe

Full Name

JPh.exe

EntryPoint

System.Void WordScramble.Program::Main()

Scope Name

JPh.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

JPh

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

238

Main Method

System.Void WordScramble.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WordScramble.FormMenuPrincipale::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

da48937212b76588c45690ad0952e04e (777.22 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙