Suspicious
Suspect

e577fd1c566f32cd83ce02d08c1e5f00

PE Executable
|
MD5: e577fd1c566f32cd83ce02d08c1e5f00
|
Size: 820.22 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
e577fd1c566f32cd83ce02d08c1e5f00
Sha1
96988391dd0da3d1cdf770a92d08d967d1241732
Sha256
df018a3644a8cc46b4acf58b6f9efefe64ae2a1eb3754eb842a171e2aff86ff0
Sha384
aaf5f9a35b0151b80818fe997800655ce3c02eb92741402cfb8522c153fedd97a2d974ac2595d88e9aab922a045778e7
Sha512
a07fa2fac7f3a84e7100590075e73b8f7e90a98541a7d3c84e2d21798975e2c37562d643f9e44196bdcf2800472e3df808290ddd24077f204c8ec2b4b012d35e
SSDeep
12288:G3KMOSPVle8cpRAWS91+2mzkhVOr2WKl+fokU7DTSFi14A:G6MArA1f+2mzk+o
TLSH
5205528C7E50E80EDF0BFC7F8AA5D1348B3169925E92410560E4AAFE87273757496B3C

PeID

HQR data file
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
dipemhnhouim
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void MkvPdOjfB.rsrFwFGTMIKbNq::fPmCnGfg(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1483

Main Method

System.Void MkvPdOjfB.rsrFwFGTMIKbNq::fPmCnGfg(System.String[])

Main IL Instruction Count

57

Main IL

ldc.r8 5937 stloc.0 <null> br IL_00EC: br IL_000F nop <null> ldloc.0 <null> ldc.r8 5952 ceq <null> brfalse IL_0076: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 3999 ldc.r8 2000 call System.Double System.Math::Tanh(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 5945.227744249483 ldc.r8 3000 call System.Double System.Math::Sqrt(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.r8 5956 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 5947 ceq <null> brfalse IL_0097: nop call System.Void MkvPdOjfB.rsrFwFGTMIKbNq::MQjHAzdvZcvHxF() ldc.r8 5952 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 5956 ceq <null> brfalse IL_00B8: nop call System.Void MkvPdOjfB.eBmjoAdnpmaUP::lZYlOczSU() ldc.r8 5958 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 5937 ceq <null> brfalse IL_00D5: nop nop <null> ldc.r8 5947 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 5958 ceq <null> brfalse IL_00EC: br IL_000F br IL_00F1: ret br IL_000F: nop ret <null>

e577fd1c566f32cd83ce02d08c1e5f00 (820.22 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙