Suspicious
Suspect

e16a1c13a330daff1dc4ee1712b95a95

PE Executable
|
MD5: e16a1c13a330daff1dc4ee1712b95a95
|
Size: 5.62 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
e16a1c13a330daff1dc4ee1712b95a95
Sha1
b0380bf35139eee81a658ce1e8c816c38a31f3fc
Sha256
6e2f8c1a53a04332f9e7df00b6b0fc583e7c1dd20d570f503b57294c5e6b977f
Sha384
8d053fcd7361915b674f9ab7daccf83135325e6430aa70822ce5feac7b29dd7b6a5e2010da54d06c49ccf03f3e4b6a0f
Sha512
c033a1215f8ebcd2605f6313b1194fd577eed3116a03bf03d61abb71765b4780728b2c4461fa28ea2e5ab642f5e702254ae76ec7b56e3c6d0246b91240091410
SSDeep
98304:kizzjAYJQ/2a9Or4cW+PvkNDHmcQq32yeDGWJ:kjKagr4cW+P8dQwnW
TLSH
6346232533D95908E67E477918788D826BF1B95B7F21CB1DBA9B13CC0F00A85AB21737

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
8qzRsNf9C1.g.resources
8qzRsNf9C1.Resources.resources
8a41d83fd4dc86.Resources.resources
bb15306e0
[NBF]root.Data
bb15306e1
[NBF]root.Data
bb15306e10
[NBF]root.Data
bb15306e100
[NBF]root.Data
bb15306e101
[NBF]root.Data
bb15306e102
[NBF]root.Data
bb15306e103
[NBF]root.Data
bb15306e104
[NBF]root.Data
bb15306e105
[NBF]root.Data
bb15306e106
[NBF]root.Data
bb15306e107
[NBF]root.Data
bb15306e108
[NBF]root.Data
bb15306e109
[NBF]root.Data
bb15306e11
[NBF]root.Data
bb15306e110
[NBF]root.Data
bb15306e111
[NBF]root.Data
bb15306e112
[NBF]root.Data
bb15306e113
[NBF]root.Data
bb15306e114
[NBF]root.Data
bb15306e115
[NBF]root.Data
bb15306e116
[NBF]root.Data
bb15306e117
[NBF]root.Data
bb15306e118
[NBF]root.Data
bb15306e119
[NBF]root.Data
bb15306e12
[NBF]root.Data
bb15306e120
[NBF]root.Data
bb15306e121
[NBF]root.Data
bb15306e122
[NBF]root.Data
bb15306e123
[NBF]root.Data
bb15306e124
[NBF]root.Data
bb15306e125
[NBF]root.Data
bb15306e126
[NBF]root.Data
bb15306e127
[NBF]root.Data
bb15306e128
[NBF]root.Data
bb15306e129
[NBF]root.Data
bb15306e13
[NBF]root.Data
bb15306e130
[NBF]root.Data
bb15306e131
[NBF]root.Data
bb15306e132
[NBF]root.Data
bb15306e133
[NBF]root.Data
bb15306e134
[NBF]root.Data
bb15306e135
[NBF]root.Data
bb15306e136
[NBF]root.Data
bb15306e137
[NBF]root.Data
bb15306e138
[NBF]root.Data
bb15306e139
[NBF]root.Data
bb15306e14
[NBF]root.Data
bb15306e140
[NBF]root.Data
bb15306e141
[NBF]root.Data
bb15306e142
[NBF]root.Data
bb15306e143
[NBF]root.Data
bb15306e144
[NBF]root.Data
bb15306e145
[NBF]root.Data
bb15306e146
[NBF]root.Data
bb15306e147
[NBF]root.Data
bb15306e148
[NBF]root.Data
bb15306e149
[NBF]root.Data
bb15306e15
[NBF]root.Data
bb15306e150
[NBF]root.Data
bb15306e151
[NBF]root.Data
bb15306e152
[NBF]root.Data
bb15306e153
[NBF]root.Data
bb15306e154
[NBF]root.Data
bb15306e155
[NBF]root.Data
bb15306e156
[NBF]root.Data
bb15306e157
[NBF]root.Data
bb15306e158
[NBF]root.Data
bb15306e159
[NBF]root.Data
bb15306e16
[NBF]root.Data
bb15306e160
[NBF]root.Data
bb15306e161
[NBF]root.Data
bb15306e162
[NBF]root.Data
bb15306e163
[NBF]root.Data
bb15306e164
[NBF]root.Data
bb15306e165
[NBF]root.Data
bb15306e166
[NBF]root.Data
bb15306e167
[NBF]root.Data
bb15306e168
[NBF]root.Data
bb15306e169
[NBF]root.Data
bb15306e17
[NBF]root.Data
bb15306e170
[NBF]root.Data
bb15306e171
[NBF]root.Data
bb15306e172
[NBF]root.Data
bb15306e173
[NBF]root.Data
bb15306e174
[NBF]root.Data
bb15306e175
[NBF]root.Data
bb15306e176
[NBF]root.Data
bb15306e177
[NBF]root.Data
bb15306e178
[NBF]root.Data
bb15306e179
[NBF]root.Data
bb15306e18
[NBF]root.Data
bb15306e180
[NBF]root.Data
bb15306e181
[NBF]root.Data
bb15306e182
[NBF]root.Data
bb15306e183
[NBF]root.Data
bb15306e184
[NBF]root.Data
bb15306e185
[NBF]root.Data
bb15306e186
[NBF]root.Data
bb15306e187
[NBF]root.Data
bb15306e188
[NBF]root.Data
bb15306e189
[NBF]root.Data
bb15306e19
[NBF]root.Data
bb15306e190
[NBF]root.Data
bb15306e191
[NBF]root.Data
bb15306e192
[NBF]root.Data
bb15306e193
[NBF]root.Data
bb15306e194
[NBF]root.Data
bb15306e195
[NBF]root.Data
bb15306e196
[NBF]root.Data
bb15306e197
[NBF]root.Data
bb15306e198
[NBF]root.Data
bb15306e199
[NBF]root.Data
bb15306e2
[NBF]root.Data
bb15306e20
[NBF]root.Data
bb15306e200
[NBF]root.Data
bb15306e201
[NBF]root.Data
bb15306e202
[NBF]root.Data
bb15306e203
[NBF]root.Data
bb15306e204
[NBF]root.Data
bb15306e205
[NBF]root.Data
bb15306e206
[NBF]root.Data
bb15306e207
[NBF]root.Data
bb15306e208
[NBF]root.Data
bb15306e209
[NBF]root.Data
bb15306e21
[NBF]root.Data
bb15306e210
[NBF]root.Data
bb15306e211
[NBF]root.Data
bb15306e212
[NBF]root.Data
bb15306e213
[NBF]root.Data
bb15306e214
[NBF]root.Data
bb15306e215
[NBF]root.Data
bb15306e216
[NBF]root.Data
bb15306e217
[NBF]root.Data
bb15306e218
[NBF]root.Data
bb15306e219
[NBF]root.Data
bb15306e22
[NBF]root.Data
bb15306e220
[NBF]root.Data
bb15306e221
[NBF]root.Data
bb15306e222
[NBF]root.Data
bb15306e223
[NBF]root.Data
bb15306e224
[NBF]root.Data
bb15306e225
[NBF]root.Data
bb15306e226
[NBF]root.Data
bb15306e227
[NBF]root.Data
bb15306e228
[NBF]root.Data
bb15306e229
[NBF]root.Data
bb15306e23
[NBF]root.Data
bb15306e230
[NBF]root.Data
bb15306e231
[NBF]root.Data
bb15306e232
[NBF]root.Data
bb15306e233
[NBF]root.Data
bb15306e234
[NBF]root.Data
bb15306e235
[NBF]root.Data
bb15306e236
[NBF]root.Data
bb15306e237
[NBF]root.Data
bb15306e238
[NBF]root.Data
bb15306e239
[NBF]root.Data
bb15306e24
[NBF]root.Data
bb15306e240
[NBF]root.Data
bb15306e241
[NBF]root.Data
bb15306e242
[NBF]root.Data
bb15306e243
[NBF]root.Data
bb15306e244
[NBF]root.Data
bb15306e245
[NBF]root.Data
bb15306e246
[NBF]root.Data
bb15306e247
[NBF]root.Data
bb15306e248
[NBF]root.Data
bb15306e249
[NBF]root.Data
bb15306e25
[NBF]root.Data
bb15306e250
[NBF]root.Data
bb15306e251
[NBF]root.Data
bb15306e252
[NBF]root.Data
bb15306e253
[NBF]root.Data
bb15306e254
[NBF]root.Data
bb15306e255
[NBF]root.Data
bb15306e256
[NBF]root.Data
bb15306e257
[NBF]root.Data
bb15306e258
[NBF]root.Data
bb15306e259
[NBF]root.Data
bb15306e26
[NBF]root.Data
bb15306e260
[NBF]root.Data
bb15306e261
[NBF]root.Data
bb15306e262
[NBF]root.Data
bb15306e263
[NBF]root.Data
bb15306e264
[NBF]root.Data
bb15306e265
[NBF]root.Data
bb15306e266
[NBF]root.Data
bb15306e267
[NBF]root.Data
bb15306e268
[NBF]root.Data
bb15306e269
[NBF]root.Data
bb15306e27
[NBF]root.Data
bb15306e270
[NBF]root.Data
bb15306e271
[NBF]root.Data
bb15306e272
[NBF]root.Data
bb15306e273
[NBF]root.Data
bb15306e274
[NBF]root.Data
bb15306e275
[NBF]root.Data
bb15306e276
[NBF]root.Data
bb15306e277
[NBF]root.Data
bb15306e278
[NBF]root.Data
bb15306e279
[NBF]root.Data
bb15306e28
[NBF]root.Data
bb15306e280
[NBF]root.Data
bb15306e281
[NBF]root.Data
bb15306e282
[NBF]root.Data
bb15306e29
[NBF]root.Data
bb15306e3
[NBF]root.Data
bb15306e30
[NBF]root.Data
bb15306e31
[NBF]root.Data
bb15306e32
[NBF]root.Data
bb15306e33
[NBF]root.Data
bb15306e34
[NBF]root.Data
bb15306e35
[NBF]root.Data
bb15306e36
[NBF]root.Data
bb15306e37
[NBF]root.Data
bb15306e38
[NBF]root.Data
bb15306e39
[NBF]root.Data
bb15306e4
[NBF]root.Data
bb15306e40
[NBF]root.Data
bb15306e41
[NBF]root.Data
bb15306e42
[NBF]root.Data
bb15306e43
[NBF]root.Data
bb15306e44
[NBF]root.Data
bb15306e45
[NBF]root.Data
bb15306e46
[NBF]root.Data
bb15306e47
[NBF]root.Data
bb15306e48
[NBF]root.Data
bb15306e49
[NBF]root.Data
bb15306e5
[NBF]root.Data
bb15306e50
[NBF]root.Data
bb15306e51
[NBF]root.Data
bb15306e52
[NBF]root.Data
bb15306e53
[NBF]root.Data
bb15306e54
[NBF]root.Data
bb15306e55
[NBF]root.Data
bb15306e56
[NBF]root.Data
bb15306e57
[NBF]root.Data
bb15306e58
[NBF]root.Data
bb15306e59
[NBF]root.Data
bb15306e6
[NBF]root.Data
bb15306e60
[NBF]root.Data
bb15306e61
[NBF]root.Data
bb15306e62
[NBF]root.Data
bb15306e63
[NBF]root.Data
bb15306e64
[NBF]root.Data
bb15306e65
[NBF]root.Data
bb15306e66
[NBF]root.Data
bb15306e67
[NBF]root.Data
bb15306e68
[NBF]root.Data
bb15306e69
[NBF]root.Data
bb15306e7
[NBF]root.Data
bb15306e70
[NBF]root.Data
bb15306e71
[NBF]root.Data
bb15306e72
[NBF]root.Data
bb15306e73
[NBF]root.Data
bb15306e74
[NBF]root.Data
bb15306e75
[NBF]root.Data
bb15306e76
[NBF]root.Data
bb15306e77
[NBF]root.Data
bb15306e78
[NBF]root.Data
bb15306e79
[NBF]root.Data
bb15306e8
[NBF]root.Data
bb15306e80
[NBF]root.Data
bb15306e81
[NBF]root.Data
bb15306e82
[NBF]root.Data
bb15306e83
[NBF]root.Data
bb15306e84
[NBF]root.Data
bb15306e85
[NBF]root.Data
bb15306e86
[NBF]root.Data
bb15306e87
[NBF]root.Data
bb15306e88
[NBF]root.Data
bb15306e89
[NBF]root.Data
bb15306e9
[NBF]root.Data
bb15306e90
[NBF]root.Data
bb15306e91
[NBF]root.Data
bb15306e92
[NBF]root.Data
bb15306e93
[NBF]root.Data
bb15306e94
[NBF]root.Data
bb15306e95
[NBF]root.Data
bb15306e96
[NBF]root.Data
bb15306e97
[NBF]root.Data
bb15306e98
[NBF]root.Data
bb15306e99
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

8qzRsNf9C1

Full Name

8qzRsNf9C1

EntryPoint

System.Void 8qzRsNf9C1.Af1yi4nYodF2/Mak5n8pW9Dqr.Qqs34::0eyMm8EjHfi52p()

Scope Name

8qzRsNf9C1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

8qzRsNf9C1

Assembly Version

2.4.36.246

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void 8qzRsNf9C1.Af1yi4nYodF2/Mak5n8pW9Dqr.Qqs34::0eyMm8EjHfi52p()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 8qzRsNf9C1.2wdCK7snonF89R::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

8qzRsNf9C1

Full Name

8qzRsNf9C1

EntryPoint

System.Void 8qzRsNf9C1.Af1yi4nYodF2/Mak5n8pW9Dqr.Qqs34::0eyMm8EjHfi52p()

Scope Name

8qzRsNf9C1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

8qzRsNf9C1

Assembly Version

2.4.36.246

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1195

Main Method

System.Void 8qzRsNf9C1.Af1yi4nYodF2/Mak5n8pW9Dqr.Qqs34::0eyMm8EjHfi52p()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 8qzRsNf9C1.2wdCK7snonF89R::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

e16a1c13a330daff1dc4ee1712b95a95 (5.62 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙