Suspicious
Suspect

dcb49b129c43fea9da4300155aa733a3

PE Executable
|
MD5: dcb49b129c43fea9da4300155aa733a3
|
Size: 566.27 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
dcb49b129c43fea9da4300155aa733a3
Sha1
26cf6a86a8f57087f7e83b483c7acd3be527255a
Sha256
4d5c94ee188d2b20cc91fa680b6a81a59a61ac93fc7e822dcd58be0310fd7768
Sha384
d48c1cbc2d6eaae3c4e45e1f9dd00ac544210af0bc71cadeed097bcfd64ddd9faa83474d0126f859b540b7392d8eed17
Sha512
75af8a9219b4b3125292dc3a9868bdadb51b28b639b8ec003fb7ebec3eab68e1bafeffad4477771739434417588757670ae4fccb7a2738a4156fbe581a1e5f12
SSDeep
12288:CLV6BtpmkrLD9efoaLgdywHIKfwQK6waJLj1kQs:gApfrLJef/0fI6wKLS9
TLSH
52C40255B7A84E2EE6DF45BAA12511528379C1E39DC3F7DE2CC464B79B227E006072C3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
Informations
Name
Value
Module Name

NanoCore Client.exe

Full Name

NanoCore Client.exe

EntryPoint

System.Void ClientLoaderForm::Main()

Scope Name

NanoCore Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NanoCore Client

Assembly Version

1.2.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

2

Main Method

System.Void ClientLoaderForm::Main()

Main IL Instruction Count

4

Main IL

call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==() callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

NanoCore Client.exe

Full Name

NanoCore Client.exe

EntryPoint

System.Void ClientLoaderForm::Main()

Scope Name

NanoCore Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

NanoCore Client

Assembly Version

1.2.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

2

Main Method

System.Void ClientLoaderForm::Main()

Main IL Instruction Count

4

Main IL

call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==() callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Artefacts
Name
Value
Embedded Resources

2

Suspicious Type Names (1-2 chars)

0

dcb49b129c43fea9da4300155aa733a3 (566.27 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
Embedded Resources

2

dcb49b129c43fea9da4300155aa733a3

Suspicious Type Names (1-2 chars)

0

dcb49b129c43fea9da4300155aa733a3

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙