Suspicious
Suspect

ebfa91b100e6f587a689b09ff58d01cc

PE Executable
|
MD5: ebfa91b100e6f587a689b09ff58d01cc
|
Size: 5.46 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
ebfa91b100e6f587a689b09ff58d01cc
Sha1
96800b813808f08d9dde861c1f442e9032390559
Sha256
cd100ddc8f101788f2f74afcf44e9cbfcd41139431901c8783505f551986b2a7
Sha384
9c9d65c78c7924bf0e05ed1f0e0d0de508fe34b4a29205345d3d42e4a0d87b2072aac05ce2f7c6897e5cec3f7806a005
Sha512
107fa1b31563649747b43bd75167241eed1c85ae92da91be0e3560b7cff6a16f67064bfb9cc5908579346242cdf5150248fe982a8f975fb9f42dc9a59b3aef83
SSDeep
49152:gRIIkFAn/2Gnw6nxwXqiMOrENcitrFkPvhGR7thSoWYfy8jg78uoX55Qq32/qenu:sUQ/2a9Or4cW+PvkNDHmsQq32yeDGWJ
TLSH
1446121A36C79544D23E837489798E42A7F0BA47AB32C71EB18B17DD8F013962723767

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
wJd12c.g.resources
wJd12c.Resources.resources
62171d5bef4424.Resources.resources
62d96f550
[NBF]root.Data
62d96f551
[NBF]root.Data
62d96f5510
[NBF]root.Data
62d96f55100
[NBF]root.Data
62d96f55101
[NBF]root.Data
62d96f55102
[NBF]root.Data
62d96f55103
[NBF]root.Data
62d96f55104
[NBF]root.Data
62d96f55105
[NBF]root.Data
62d96f55106
[NBF]root.Data
62d96f55107
[NBF]root.Data
62d96f55108
[NBF]root.Data
62d96f55109
[NBF]root.Data
62d96f5511
[NBF]root.Data
62d96f55110
[NBF]root.Data
62d96f55111
[NBF]root.Data
62d96f55112
[NBF]root.Data
62d96f55113
[NBF]root.Data
62d96f55114
[NBF]root.Data
62d96f55115
[NBF]root.Data
62d96f55116
[NBF]root.Data
62d96f55117
[NBF]root.Data
62d96f55118
[NBF]root.Data
62d96f55119
[NBF]root.Data
62d96f5512
[NBF]root.Data
62d96f55120
[NBF]root.Data
62d96f55121
[NBF]root.Data
62d96f55122
[NBF]root.Data
62d96f55123
[NBF]root.Data
62d96f55124
[NBF]root.Data
62d96f55125
[NBF]root.Data
62d96f55126
[NBF]root.Data
62d96f55127
[NBF]root.Data
62d96f55128
[NBF]root.Data
62d96f55129
[NBF]root.Data
62d96f5513
[NBF]root.Data
62d96f55130
[NBF]root.Data
62d96f55131
[NBF]root.Data
62d96f55132
[NBF]root.Data
62d96f55133
[NBF]root.Data
62d96f55134
[NBF]root.Data
62d96f55135
[NBF]root.Data
62d96f55136
[NBF]root.Data
62d96f55137
[NBF]root.Data
62d96f55138
[NBF]root.Data
62d96f55139
[NBF]root.Data
62d96f5514
[NBF]root.Data
62d96f55140
[NBF]root.Data
62d96f55141
[NBF]root.Data
62d96f55142
[NBF]root.Data
62d96f55143
[NBF]root.Data
62d96f55144
[NBF]root.Data
62d96f55145
[NBF]root.Data
62d96f55146
[NBF]root.Data
62d96f55147
[NBF]root.Data
62d96f55148
[NBF]root.Data
62d96f55149
[NBF]root.Data
62d96f5515
[NBF]root.Data
62d96f55150
[NBF]root.Data
62d96f55151
[NBF]root.Data
62d96f55152
[NBF]root.Data
62d96f55153
[NBF]root.Data
62d96f55154
[NBF]root.Data
62d96f55155
[NBF]root.Data
62d96f55156
[NBF]root.Data
62d96f55157
[NBF]root.Data
62d96f55158
[NBF]root.Data
62d96f55159
[NBF]root.Data
62d96f5516
[NBF]root.Data
62d96f55160
[NBF]root.Data
62d96f55161
[NBF]root.Data
62d96f55162
[NBF]root.Data
62d96f55163
[NBF]root.Data
62d96f55164
[NBF]root.Data
62d96f55165
[NBF]root.Data
62d96f55166
[NBF]root.Data
62d96f55167
[NBF]root.Data
62d96f55168
[NBF]root.Data
62d96f55169
[NBF]root.Data
62d96f5517
[NBF]root.Data
62d96f55170
[NBF]root.Data
62d96f55171
[NBF]root.Data
62d96f55172
[NBF]root.Data
62d96f55173
[NBF]root.Data
62d96f55174
[NBF]root.Data
62d96f55175
[NBF]root.Data
62d96f55176
[NBF]root.Data
62d96f55177
[NBF]root.Data
62d96f55178
[NBF]root.Data
62d96f55179
[NBF]root.Data
62d96f5518
[NBF]root.Data
62d96f55180
[NBF]root.Data
62d96f55181
[NBF]root.Data
62d96f55182
[NBF]root.Data
62d96f55183
[NBF]root.Data
62d96f55184
[NBF]root.Data
62d96f55185
[NBF]root.Data
62d96f55186
[NBF]root.Data
62d96f55187
[NBF]root.Data
62d96f55188
[NBF]root.Data
62d96f55189
[NBF]root.Data
62d96f5519
[NBF]root.Data
62d96f55190
[NBF]root.Data
62d96f55191
[NBF]root.Data
62d96f55192
[NBF]root.Data
62d96f55193
[NBF]root.Data
62d96f55194
[NBF]root.Data
62d96f55195
[NBF]root.Data
62d96f55196
[NBF]root.Data
62d96f55197
[NBF]root.Data
62d96f55198
[NBF]root.Data
62d96f55199
[NBF]root.Data
62d96f552
[NBF]root.Data
62d96f5520
[NBF]root.Data
62d96f55200
[NBF]root.Data
62d96f55201
[NBF]root.Data
62d96f55202
[NBF]root.Data
62d96f55203
[NBF]root.Data
62d96f55204
[NBF]root.Data
62d96f55205
[NBF]root.Data
62d96f55206
[NBF]root.Data
62d96f55207
[NBF]root.Data
62d96f55208
[NBF]root.Data
62d96f55209
[NBF]root.Data
62d96f5521
[NBF]root.Data
62d96f55210
[NBF]root.Data
62d96f55211
[NBF]root.Data
62d96f55212
[NBF]root.Data
62d96f55213
[NBF]root.Data
62d96f55214
[NBF]root.Data
62d96f55215
[NBF]root.Data
62d96f55216
[NBF]root.Data
62d96f55217
[NBF]root.Data
62d96f55218
[NBF]root.Data
62d96f55219
[NBF]root.Data
62d96f5522
[NBF]root.Data
62d96f55220
[NBF]root.Data
62d96f55221
[NBF]root.Data
62d96f55222
[NBF]root.Data
62d96f55223
[NBF]root.Data
62d96f55224
[NBF]root.Data
62d96f55225
[NBF]root.Data
62d96f55226
[NBF]root.Data
62d96f55227
[NBF]root.Data
62d96f55228
[NBF]root.Data
62d96f55229
[NBF]root.Data
62d96f5523
[NBF]root.Data
62d96f55230
[NBF]root.Data
62d96f55231
[NBF]root.Data
62d96f55232
[NBF]root.Data
62d96f55233
[NBF]root.Data
62d96f55234
[NBF]root.Data
62d96f55235
[NBF]root.Data
62d96f55236
[NBF]root.Data
62d96f55237
[NBF]root.Data
62d96f55238
[NBF]root.Data
62d96f55239
[NBF]root.Data
62d96f5524
[NBF]root.Data
62d96f55240
[NBF]root.Data
62d96f55241
[NBF]root.Data
62d96f55242
[NBF]root.Data
62d96f55243
[NBF]root.Data
62d96f55244
[NBF]root.Data
62d96f55245
[NBF]root.Data
62d96f55246
[NBF]root.Data
62d96f55247
[NBF]root.Data
62d96f55248
[NBF]root.Data
62d96f55249
[NBF]root.Data
62d96f5525
[NBF]root.Data
62d96f55250
[NBF]root.Data
62d96f55251
[NBF]root.Data
62d96f55252
[NBF]root.Data
62d96f55253
[NBF]root.Data
62d96f55254
[NBF]root.Data
62d96f55255
[NBF]root.Data
62d96f55256
[NBF]root.Data
62d96f55257
[NBF]root.Data
62d96f55258
[NBF]root.Data
62d96f55259
[NBF]root.Data
62d96f5526
[NBF]root.Data
62d96f55260
[NBF]root.Data
62d96f55261
[NBF]root.Data
62d96f55262
[NBF]root.Data
62d96f55263
[NBF]root.Data
62d96f55264
[NBF]root.Data
62d96f55265
[NBF]root.Data
62d96f55266
[NBF]root.Data
62d96f55267
[NBF]root.Data
62d96f55268
[NBF]root.Data
62d96f55269
[NBF]root.Data
62d96f5527
[NBF]root.Data
62d96f55270
[NBF]root.Data
62d96f55271
[NBF]root.Data
62d96f55272
[NBF]root.Data
62d96f55273
[NBF]root.Data
62d96f55274
[NBF]root.Data
62d96f55275
[NBF]root.Data
62d96f55276
[NBF]root.Data
62d96f55277
[NBF]root.Data
62d96f55278
[NBF]root.Data
62d96f55279
[NBF]root.Data
62d96f5528
[NBF]root.Data
62d96f55280
[NBF]root.Data
62d96f55281
[NBF]root.Data
62d96f55282
[NBF]root.Data
62d96f5529
[NBF]root.Data
62d96f553
[NBF]root.Data
62d96f5530
[NBF]root.Data
62d96f5531
[NBF]root.Data
62d96f5532
[NBF]root.Data
62d96f5533
[NBF]root.Data
62d96f5534
[NBF]root.Data
62d96f5535
[NBF]root.Data
62d96f5536
[NBF]root.Data
62d96f5537
[NBF]root.Data
62d96f5538
[NBF]root.Data
62d96f5539
[NBF]root.Data
62d96f554
[NBF]root.Data
62d96f5540
[NBF]root.Data
62d96f5541
[NBF]root.Data
62d96f5542
[NBF]root.Data
62d96f5543
[NBF]root.Data
62d96f5544
[NBF]root.Data
62d96f5545
[NBF]root.Data
62d96f5546
[NBF]root.Data
62d96f5547
[NBF]root.Data
62d96f5548
[NBF]root.Data
62d96f5549
[NBF]root.Data
62d96f555
[NBF]root.Data
62d96f5550
[NBF]root.Data
62d96f5551
[NBF]root.Data
62d96f5552
[NBF]root.Data
62d96f5553
[NBF]root.Data
62d96f5554
[NBF]root.Data
62d96f5555
[NBF]root.Data
62d96f5556
[NBF]root.Data
62d96f5557
[NBF]root.Data
62d96f5558
[NBF]root.Data
62d96f5559
[NBF]root.Data
62d96f556
[NBF]root.Data
62d96f5560
[NBF]root.Data
62d96f5561
[NBF]root.Data
62d96f5562
[NBF]root.Data
62d96f5563
[NBF]root.Data
62d96f5564
[NBF]root.Data
62d96f5565
[NBF]root.Data
62d96f5566
[NBF]root.Data
62d96f5567
[NBF]root.Data
62d96f5568
[NBF]root.Data
62d96f5569
[NBF]root.Data
62d96f557
[NBF]root.Data
62d96f5570
[NBF]root.Data
62d96f5571
[NBF]root.Data
62d96f5572
[NBF]root.Data
62d96f5573
[NBF]root.Data
62d96f5574
[NBF]root.Data
62d96f5575
[NBF]root.Data
62d96f5576
[NBF]root.Data
62d96f5577
[NBF]root.Data
62d96f5578
[NBF]root.Data
62d96f5579
[NBF]root.Data
62d96f558
[NBF]root.Data
62d96f5580
[NBF]root.Data
62d96f5581
[NBF]root.Data
62d96f5582
[NBF]root.Data
62d96f5583
[NBF]root.Data
62d96f5584
[NBF]root.Data
62d96f5585
[NBF]root.Data
62d96f5586
[NBF]root.Data
62d96f5587
[NBF]root.Data
62d96f5588
[NBF]root.Data
62d96f5589
[NBF]root.Data
62d96f559
[NBF]root.Data
62d96f5590
[NBF]root.Data
62d96f5591
[NBF]root.Data
62d96f5592
[NBF]root.Data
62d96f5593
[NBF]root.Data
62d96f5594
[NBF]root.Data
62d96f5595
[NBF]root.Data
62d96f5596
[NBF]root.Data
62d96f5597
[NBF]root.Data
62d96f5598
[NBF]root.Data
62d96f5599
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

wJd12c

Full Name

wJd12c

EntryPoint

System.Void wJd12c.0PfbWg7d2::nJs0N7p()

Scope Name

wJd12c

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

wJd12c

Assembly Version

16.4.11.249

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void wJd12c.0PfbWg7d2::nJs0N7p()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void wJd12c.0PfbWg7d2::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken wJd12c.0PfbWg7d2 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass wJd12c.0PfbWg7d2 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] wJd12c.fKz36dgYwLs57b::0rxQyPd6o2Rj(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void wJd12c.Xyx05zBfem/Kg0rc5Ec2Ci.8Bqixe7L::Tq8dw3aJ(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

Module Name

wJd12c

Full Name

wJd12c

EntryPoint

System.Void wJd12c.0PfbWg7d2::nJs0N7p()

Scope Name

wJd12c

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

wJd12c

Assembly Version

16.4.11.249

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void wJd12c.0PfbWg7d2::nJs0N7p()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void wJd12c.0PfbWg7d2::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken wJd12c.0PfbWg7d2 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass wJd12c.0PfbWg7d2 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] wJd12c.fKz36dgYwLs57b::0rxQyPd6o2Rj(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void wJd12c.Xyx05zBfem/Kg0rc5Ec2Ci.8Bqixe7L::Tq8dw3aJ(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

ebfa91b100e6f587a689b09ff58d01cc (5.46 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙