Suspicious
Suspect

dfadc09e24690bfb235a2179d8b959a7

PE Executable
|
MD5: dfadc09e24690bfb235a2179d8b959a7
|
Size: 57.86 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
dfadc09e24690bfb235a2179d8b959a7
Sha1
448840f4ceb26bd47ed68327cd3e6f49218a81c0
Sha256
b0ba0635a62546f26ab6ceb0d8dfde7e0a04122bd9f23c039d51b1a8df842e7e
Sha384
2937e03deb883d3f482c7509ce1ac923dbd6c099cfb6e5d2d5f9a36fd27e0f10694f08d8f0d043bd22b951daa72d6159
Sha512
cec3c582f3b204e01b6aa5468dcd55063bbf0bb6bb3287b1282d617a6781d07af7aeca496d5b31313a607e42de11af042c5da92b3763ddadd854ef441c6c570c
SSDeep
768:kv4iv4zcVwGMy6VVc9yREY2J0Z7DAq2XGlvIQ6eIdWgcQEiJeheNsYdChaEnsltB:kvwSDq/gQ6eiHc2tXCHsltYnEx
TLSH
C143194DA3BC8223FA6F8ABD697185C746F6B21AD522FF8D0CCCA4E424A538556007D7

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Sys.Properties.Resources.resources
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ?

Module Name

OpenJDK Platform binary.exe

Full Name

OpenJDK Platform binary.exe

EntryPoint

System.Void FriendlyTool.Program::Main(System.String[])

Scope Name

OpenJDK Platform binary.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OpenJDK Platform binary

Assembly Version

17.0.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

240

Main Method

System.Void FriendlyTool.Program::Main(System.String[])

Main IL Instruction Count

116

Main IL

newobj System.Void FriendlyTool.Program/<>c__DisplayClass0_0::.ctor() stloc.0 <null> ldloc.0 <null> ldarg.0 <null> stfld System.String[] FriendlyTool.Program/<>c__DisplayClass0_0::args ldstr C:\Dump.kke stloc.1 <null> call System.String System.Environment::get_MachineName() stloc.2 <null> ldloc.2 <null> ldstr Z call System.Boolean System.String::op_Equality(System.String,System.String) brtrue.s IL_0033: ldloc.1 ldloc.2 <null> ldstr SIMA123 call System.Boolean System.String::op_Equality(System.String,System.String) brfalse.s IL_005C: ldc.i4.1 ldloc.1 <null> call System.Boolean System.IO.File::Exists(System.String) brfalse.s IL_005C: ldc.i4.1 ldloc.1 <null> call System.String System.IO.File::ReadAllText(System.String) callvirt System.String System.String::Trim() ldstr Onion call System.Boolean System.String::op_Equality(System.String,System.String) brfalse.s IL_0057: leave.s IL_005C leave IL_0156: ret leave.s IL_005C: ldc.i4.1 pop <null> leave.s IL_005C: ldc.i4.1 ldc.i4.1 <null> ldstr FriendlyTool ldloca.s V_3 newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String,System.Boolean&) stloc.s V_4 ldloc.3 <null> brtrue.s IL_007D: ldnull ldstr Another instance of the application is already running. call System.Void System.Console::WriteLine(System.String) leave IL_0156: ret ldnull <null> stloc.s V_5 ldnull <null> stloc.s V_6 ldnull <null> stloc.s V_7 newobj System.Void FriendlyTool.ErrorLogger::.ctor() stloc.s V_5 newobj System.Void FriendlyTool.ConsoleService::.ctor() stloc.s V_8 ldloc.s V_5 newobj System.Void FriendlyTool.SystemChecker::.ctor(FriendlyTool.IErrorLogger) stloc.s V_9 ldloc.s V_5 newobj System.Void FriendlyTool.SystemData::.ctor(FriendlyTool.IErrorLogger) stloc.s V_10 ldloc.s V_5 newobj System.Void FriendlyTool.FileDownloader::.ctor(FriendlyTool.IErrorLogger) stloc.s V_6 ldloc.s V_5 ldloc.s V_6 newobj System.Void FriendlyTool.DataUploader::.ctor(FriendlyTool.IErrorLogger,FriendlyTool.IFileDownloader) stloc.s V_11 ldloc.s V_5 ldloc.s V_11 newobj System.Void FriendlyTool.DataHandler::.ctor(FriendlyTool.IErrorLogger,FriendlyTool.IDataUploader) stloc.s V_7 ldloc.0 <null> ldloc.s V_8 ldloc.s V_9 ldloc.s V_10 ldloc.s V_7 ldloc.s V_5 ldloc.s V_6 newobj System.Void FriendlyTool.Core::.ctor(FriendlyTool.IConsoleService,FriendlyTool.ISystemChecker,FriendlyTool.ISystemDataService,FriendlyTool.IDataHandler,FriendlyTool.IErrorLogger,FriendlyTool.IFileDownloader) stfld FriendlyTool.Core FriendlyTool.Program/<>c__DisplayClass0_0::core ldloc.0 <null> ldftn System.Threading.Tasks.Task FriendlyTool.Program/<>c__DisplayClass0_0::<Main>b__0() newobj System.Void System.Func`1<System.Threading.Tasks.Task>::.ctor(System.Object,System.IntPtr) call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Func`1<System.Threading.Tasks.Task>) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_12 ldloca.s V_12 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() leave.s IL_0156: ret stloc.s V_13 ldstr Critical startup error: ldloc.s V_13 callvirt System.String System.Exception::get_Message() call System.String System.String::Concat(System.String,System.String) call System.Void System.Console::WriteLine(System.String) leave.s IL_0156: ret ldloc.s V_5 brfalse.s IL_0122: ldloc.s V_6 ldloc.s V_5 callvirt System.Void System.IDisposable::Dispose() ldloc.s V_6 brfalse.s IL_012D: ldloc.s V_7 ldloc.s V_6 callvirt System.Void System.IDisposable::Dispose() ldloc.s V_7 isinst System.IDisposable dup <null> brtrue.s IL_013A: callvirt System.Void System.IDisposable::Dispose() pop <null> br.s IL_013F: call System.Void System.GC::Collect() callvirt System.Void System.IDisposable::Dispose() call System.Void System.GC::Collect() call System.Void System.GC::WaitForPendingFinalizers() endfinally <null> ldloc.s V_4 brfalse.s IL_0155: endfinally ldloc.s V_4 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null>

Module Name

OpenJDK Platform binary.exe

Full Name

OpenJDK Platform binary.exe

EntryPoint

System.Void FriendlyTool.Program::Main(System.String[])

Scope Name

OpenJDK Platform binary.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OpenJDK Platform binary

Assembly Version

17.0.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

240

Main Method

System.Void FriendlyTool.Program::Main(System.String[])

Main IL Instruction Count

116

Main IL

newobj System.Void FriendlyTool.Program/<>c__DisplayClass0_0::.ctor() stloc.0 <null> ldloc.0 <null> ldarg.0 <null> stfld System.String[] FriendlyTool.Program/<>c__DisplayClass0_0::args ldstr C:\Dump.kke stloc.1 <null> call System.String System.Environment::get_MachineName() stloc.2 <null> ldloc.2 <null> ldstr Z call System.Boolean System.String::op_Equality(System.String,System.String) brtrue.s IL_0033: ldloc.1 ldloc.2 <null> ldstr SIMA123 call System.Boolean System.String::op_Equality(System.String,System.String) brfalse.s IL_005C: ldc.i4.1 ldloc.1 <null> call System.Boolean System.IO.File::Exists(System.String) brfalse.s IL_005C: ldc.i4.1 ldloc.1 <null> call System.String System.IO.File::ReadAllText(System.String) callvirt System.String System.String::Trim() ldstr Onion call System.Boolean System.String::op_Equality(System.String,System.String) brfalse.s IL_0057: leave.s IL_005C leave IL_0156: ret leave.s IL_005C: ldc.i4.1 pop <null> leave.s IL_005C: ldc.i4.1 ldc.i4.1 <null> ldstr FriendlyTool ldloca.s V_3 newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String,System.Boolean&) stloc.s V_4 ldloc.3 <null> brtrue.s IL_007D: ldnull ldstr Another instance of the application is already running. call System.Void System.Console::WriteLine(System.String) leave IL_0156: ret ldnull <null> stloc.s V_5 ldnull <null> stloc.s V_6 ldnull <null> stloc.s V_7 newobj System.Void FriendlyTool.ErrorLogger::.ctor() stloc.s V_5 newobj System.Void FriendlyTool.ConsoleService::.ctor() stloc.s V_8 ldloc.s V_5 newobj System.Void FriendlyTool.SystemChecker::.ctor(FriendlyTool.IErrorLogger) stloc.s V_9 ldloc.s V_5 newobj System.Void FriendlyTool.SystemData::.ctor(FriendlyTool.IErrorLogger) stloc.s V_10 ldloc.s V_5 newobj System.Void FriendlyTool.FileDownloader::.ctor(FriendlyTool.IErrorLogger) stloc.s V_6 ldloc.s V_5 ldloc.s V_6 newobj System.Void FriendlyTool.DataUploader::.ctor(FriendlyTool.IErrorLogger,FriendlyTool.IFileDownloader) stloc.s V_11 ldloc.s V_5 ldloc.s V_11 newobj System.Void FriendlyTool.DataHandler::.ctor(FriendlyTool.IErrorLogger,FriendlyTool.IDataUploader) stloc.s V_7 ldloc.0 <null> ldloc.s V_8 ldloc.s V_9 ldloc.s V_10 ldloc.s V_7 ldloc.s V_5 ldloc.s V_6 newobj System.Void FriendlyTool.Core::.ctor(FriendlyTool.IConsoleService,FriendlyTool.ISystemChecker,FriendlyTool.ISystemDataService,FriendlyTool.IDataHandler,FriendlyTool.IErrorLogger,FriendlyTool.IFileDownloader) stfld FriendlyTool.Core FriendlyTool.Program/<>c__DisplayClass0_0::core ldloc.0 <null> ldftn System.Threading.Tasks.Task FriendlyTool.Program/<>c__DisplayClass0_0::<Main>b__0() newobj System.Void System.Func`1<System.Threading.Tasks.Task>::.ctor(System.Object,System.IntPtr) call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Func`1<System.Threading.Tasks.Task>) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_12 ldloca.s V_12 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() leave.s IL_0156: ret stloc.s V_13 ldstr Critical startup error: ldloc.s V_13 callvirt System.String System.Exception::get_Message() call System.String System.String::Concat(System.String,System.String) call System.Void System.Console::WriteLine(System.String) leave.s IL_0156: ret ldloc.s V_5 brfalse.s IL_0122: ldloc.s V_6 ldloc.s V_5 callvirt System.Void System.IDisposable::Dispose() ldloc.s V_6 brfalse.s IL_012D: ldloc.s V_7 ldloc.s V_6 callvirt System.Void System.IDisposable::Dispose() ldloc.s V_7 isinst System.IDisposable dup <null> brtrue.s IL_013A: callvirt System.Void System.IDisposable::Dispose() pop <null> br.s IL_013F: call System.Void System.GC::Collect() callvirt System.Void System.IDisposable::Dispose() call System.Void System.GC::Collect() call System.Void System.GC::WaitForPendingFinalizers() endfinally <null> ldloc.s V_4 brfalse.s IL_0155: endfinally ldloc.s V_4 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null>

dfadc09e24690bfb235a2179d8b959a7 (57.86 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙