Suspicious
Suspect

e481069cf2a151b3c4f90c630223db13

PE Executable
|
MD5: e481069cf2a151b3c4f90c630223db13
|
Size: 1.08 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
e481069cf2a151b3c4f90c630223db13
Sha1
ec9b99e2caed243fc255b4512dd74e1b4d475f53
Sha256
77be2ee5c55a9c5f20b6522fb6fbd174465481ad60b5143c95ee31e16fccaf8e
Sha384
860faaf3ae430bfb4c6e557c325705fd3de1343509d61d593190dcad644fd0808760c69d4f167859d5dca567a090acd4
Sha512
3a9ba42076fb2bfe67063cb52aed5b4e391ffe6c139caebb50741ecf934bbfe531434714dfd926d91626c6239fb66139155d4c6bb489da1bf9761035593df713
SSDeep
12288:2r6/wUKCowCFzNX7+sgWZz4LzzeVuoFuyZym5hGCnTMVVuttiZE9e7JxsIvzHjbV:HTTcNXSWZz47DUXZLuVKsE8Ny
TLSH
3035F158229ACA02E1E55FF12972E2F407787EDED820D3578FDAAEDF7865B804509343
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FontManager.Form1.resources
FontManager.Properties.Resources.resources
LAN
[NBF]root.Data
WAN
[NBF]root.Data
lqOom
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: nmqPk.pdb

Module Name

nmqPk.exe

Full Name

nmqPk.exe

EntryPoint

System.Void FontManager.Program::Main()

Scope Name

nmqPk.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

nmqPk

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

358

Main Method

System.Void FontManager.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void FontManager.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

e481069cf2a151b3c4f90c630223db13 (1.08 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FontManager.Form1.resources
FontManager.Properties.Resources.resources
LAN
[NBF]root.Data
WAN
[NBF]root.Data
lqOom
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙