Suspicious
Suspect

dbdb784d4f368de6be3297085a62c9ae

PE Executable
|
MD5: dbdb784d4f368de6be3297085a62c9ae
|
Size: 1.08 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
dbdb784d4f368de6be3297085a62c9ae
Sha1
dae23d00f539d7626385acfd135694694f982b65
Sha256
d1f3c5e1300ab1be652860818d9f82bc06b91cddad6d0a46eb7ea726524de100
Sha384
14b237cdb5a260d55663dd01c185e35c88b62bd13f3d37b7acc3251aada6e6f27ad00a873f2fe68ec05db99d7fd99c4f
Sha512
b899866059927afe7fd35ae5cd359ee39fa7cfdfe7562558b6ec8c09c161dec1e5fede8e4ffa50a485822e829d2dfd6e1ab9e502a71f9e9d5ecb03e36904ce50
SSDeep
24576:bvW69Ckq9fvq1F+xH80lS5hSMwyr0X9S/Vs+vW:1Qv6mxHtllXXk/
TLSH
C53502942706D116C994E3385E71F3F8265C1EEAB510E313AFEDBF6BBDAAD164C40182

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsConquest.GameForm.resources
$this.Icon
[NBF]root.IconData
UHD
[NBF]root.Data
WindowsConquest.Properties.Resources.resources
PANZ
[NBF]root.Data
[NBF]root.Data-preview.png
manivela1b
[NBF]root.Data
[NBF]root.Data-preview.png
manivela3b
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\RmxkpiyHeH\src\obj\Debug\aFBu.pdb

Module Name

aFBu.exe

Full Name

aFBu.exe

EntryPoint

System.Void WindowsConquest.Program::Main()

Scope Name

aFBu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

aFBu

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

46

Main Method

System.Void WindowsConquest.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsConquest.GameForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

aFBu.exe

Full Name

aFBu.exe

EntryPoint

System.Void WindowsConquest.Program::Main()

Scope Name

aFBu.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

aFBu

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

46

Main Method

System.Void WindowsConquest.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void WindowsConquest.GameForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

dbdb784d4f368de6be3297085a62c9ae (1.08 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsConquest.GameForm.resources
$this.Icon
[NBF]root.IconData
UHD
[NBF]root.Data
WindowsConquest.Properties.Resources.resources
PANZ
[NBF]root.Data
[NBF]root.Data-preview.png
manivela1b
[NBF]root.Data
[NBF]root.Data-preview.png
manivela3b
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙