Suspicious
Suspect

ecc4e10875a36e766bb5a900fdc8e300

PE Executable
|
MD5: ecc4e10875a36e766bb5a900fdc8e300
|
Size: 705.02 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
ecc4e10875a36e766bb5a900fdc8e300
Sha1
a6aae30a083eb99b38a12efead21240dcd08b20f
Sha256
a6aad4cbcdc31807497d1cae2c34ec63f8bcaeb99c20bcc742e3fd48802c13ca
Sha384
55d5a6e7bf5d630b39d0eb9d86a281bf7ba55fd72fc495ff2676c59db34e1739c43e84c865c91d94bdcec71822b780d2
Sha512
9786d03e029345d55ac715db61bf14b6b71ceb1b34640a9641e765dceae03a3985d39af21d85081fd09638e88a63c4fd379ee3c17100a00daf8b56a609b7baeb
SSDeep
12288:QHKA34WEC7uv02U8m3a1cXtvE0a/EQoSUenRjSYGGd0EPB7JU6oyUu4P4+/NYpD9:QHKA34w/2DmecrrQXXWYGG3PBtSvuu4/
TLSH
35E412503A6DE612D4B11FF00C31D27017B9AE9D9A22EB8B4ECD2DEF7175B459222B07
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TextTools.Forms.MainForm.resources
TextTools.Properties.Resources.resources
Mars
[NBF]root.Data
vyym
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: HHXy.pdb

Module Name

HHXy.exe

Full Name

HHXy.exe

EntryPoint

System.Void TextTools.Program::Main()

Scope Name

HHXy.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

HHXy

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

204

Main Method

System.Void TextTools.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void TextTools.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

ecc4e10875a36e766bb5a900fdc8e300 (705.02 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙