Suspicious
Suspect

eac8b8c88719d4dd85e8bd882e9cdba7

PE Executable
|
MD5: eac8b8c88719d4dd85e8bd882e9cdba7
|
Size: 678.91 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
eac8b8c88719d4dd85e8bd882e9cdba7
Sha1
d028a5cfc1c1e4d2e9b924691b21ba3dc66d281c
Sha256
a22cff1b630771a330a605a71829ad0a113446b40a38044b5b5ce55df6cc2fc8
Sha384
4809f07295f0a0a4ec0e8fafca225a815997102bd303b99a9ece1d766395f171ca7bc1d6d5a79c508b9e2f1afc94d3ff
Sha512
da28cf7c9ff211f6cdecd1ceb4a86d2e9745ad7301685d2ae16a02d595c996af48a7b3df8d2b09d170a68aebeb50f3db8b25f2de1a96579b6fe2bef67a4f3be1
SSDeep
12288:72Qmq+el4bna99RJA1mEZCXwsfaP2EgN1Ad4SgFs/MbkmKjIgs:JmrelwYJA23iP2EmeMbkZcgs
TLSH
81E41250277AD602DAA95B3129B1E67107BA3DA9E831D35A9FD87DEFB871F008D00353

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChineseRemainder.Forms.MainForm.resources
ChineseRemainder.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
nISj
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: VvEZ.pdb

Module Name

VvEZ.exe

Full Name

VvEZ.exe

EntryPoint

System.Void ChineseRemainder.Program::Main()

Scope Name

VvEZ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

VvEZ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

163

Main Method

System.Void ChineseRemainder.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ChineseRemainder.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

VvEZ.exe

Full Name

VvEZ.exe

EntryPoint

System.Void ChineseRemainder.Program::Main()

Scope Name

VvEZ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

VvEZ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

163

Main Method

System.Void ChineseRemainder.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ChineseRemainder.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

eac8b8c88719d4dd85e8bd882e9cdba7 (678.91 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChineseRemainder.Forms.MainForm.resources
ChineseRemainder.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
nISj
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙