Suspicious
Suspect

dd9b16756a39b4c2224c0b868cc6c55a

PE Executable
|
MD5: dd9b16756a39b4c2224c0b868cc6c55a
|
Size: 707.58 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
dd9b16756a39b4c2224c0b868cc6c55a
Sha1
436daaf5795188494542bc09d8a61f5d9de59be4
Sha256
c77df447c372e2aa22b4fb528775f2ac2be22e0595f02ceb3c40c9944cf689d4
Sha384
5ae8580895cf60d6aba73ee6f657ab70ccef56212660ed76280da5c70afd70eb7aefa555d5d199ebb8f30690045a73e0
Sha512
89e775b0306d41bfac7883785188b964ad8741c57a98b38864035a0ab1ad6173031f9b8fc99e2730b314bfed87572feb2a6e4e58b3e7c0fd394b3854853a50a9
SSDeep
12288:n09j7WqbdvnJ5NCBzrX/pybJ2lTT8mEszdniNFJHYTQJyUTlgoK683VgJ4+iq:Ej7WqbFNCdMiTgCoX4CCoK6Qgmq
TLSH
8AE402883A11D817CA929BB41871F278133A5EDDF520D286BFE96DDFB9B5F204D40293

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
yCJZ
[NBF]root.Data
[NBF]root.Data-preview.png
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ?

Module Name

tvuL.exe

Full Name

tvuL.exe

EntryPoint

System.Void EstudoTaskool.Program::Main()

Scope Name

tvuL.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

tvuL

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

144

Main Method

System.Void EstudoTaskool.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void EstudoTaskool.FrmPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

Module Name

tvuL.exe

Full Name

tvuL.exe

EntryPoint

System.Void EstudoTaskool.Program::Main()

Scope Name

tvuL.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

tvuL

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

144

Main Method

System.Void EstudoTaskool.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) newobj System.Void EstudoTaskool.FrmPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null>

dd9b16756a39b4c2224c0b868cc6c55a (707.58 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙