Suspicious
Suspect

eef01da8c18de3fc7869717f93721038

PE Executable
|
MD5: eef01da8c18de3fc7869717f93721038
|
Size: 1.16 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
eef01da8c18de3fc7869717f93721038
Sha1
0368f5868e786fb4f1622116165684e35d6c23b5
Sha256
46ebf0713b673f18360202e297685e3031456bf7d44a4ec97bbdc6187c716bc8
Sha384
d01beac64e3734327d9bdce4ee2edd0e2af199f19e69d071f9c76d17f35a0ad2bd3ccd7bfe3ccec35aa8ac9154cddd11
Sha512
a61d87e94357b56c9a8e678988f559d98983315ca45086cc89eb0db15056e4bebbb3f0054823ad404fca6cff9812d6e8d82c4bb26f6b6458c808b57bbc17fd17
SSDeep
12288:aFaCcFPRxtAQJPZe62IWjppUHXDOWiLMg2nQhrB62pgJm4C6qjj9VW4NikEbw73c:HpLj3e62HjppUHXCWiogptjQojrNNi7
TLSH
F335E09C3365B59FC467CE7189A4DE70AA606CA6971BC20351E71DAFB90C6C7CE102F2

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
Teacher
[NBF]root.Data
kzud
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

qtua.exe

Full Name

qtua.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

qtua.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

qtua

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

43

Main IL

nop <null> ldc.i4 -1898410617 ldc.i4 -478737954 xor <null> dup <null> stloc.0 <null> ldc.i4.6 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0083: ret call System.Void ClipboardAnalyzer.Program::‌‫‮‎‍‫‌‬‏‎‮​‏‍‬‬‪‭‪‌‮‎​‬‫‌‌‮() ldloc.0 <null> ldc.i4 -840630913 mul <null> ldc.i4 -1661887635 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‫‌‬‎‭​‌‭‪‮‭‍‎​‪‬‪‪‌‬‏‫‭‮‬‮(System.Boolean) ldloc.0 <null> ldc.i4 1015382395 mul <null> ldc.i4 1012639169 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‏‫​‎‮‫​‮‮‏‮‬​‫‏​‬‬‬‍‭‌​​‪‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1256267674 mul <null> ldc.i4 837282822 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> ldloc.0 <null> ldc.i4 241164259 mul <null> ldc.i4 -163157807 xor <null> br.s IL_0006: ldc.i4 -478737954 ret <null>

Module Name

qtua.exe

Full Name

qtua.exe

EntryPoint

System.Void ClipboardAnalyzer.Program::Main()

Scope Name

qtua.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

qtua

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

367

Main Method

System.Void ClipboardAnalyzer.Program::Main()

Main IL Instruction Count

43

Main IL

nop <null> ldc.i4 -1898410617 ldc.i4 -478737954 xor <null> dup <null> stloc.0 <null> ldc.i4.6 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br.s IL_0083: ret call System.Void ClipboardAnalyzer.Program::‌‫‮‎‍‫‌‬‏‎‮​‏‍‬‬‪‭‪‌‮‎​‬‫‌‌‮() ldloc.0 <null> ldc.i4 -840630913 mul <null> ldc.i4 -1661887635 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> ldc.i4.0 <null> call System.Void ClipboardAnalyzer.Program::‫‌‬‎‭​‌‭‪‮‭‍‎​‪‬‪‪‌‬‏‫‭‮‬‮(System.Boolean) ldloc.0 <null> ldc.i4 1015382395 mul <null> ldc.i4 1012639169 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> newobj System.Void ClipboardAnalyzer.MainForm::.ctor() call System.Void ClipboardAnalyzer.Program::‏‫​‎‮‫​‮‮‏‮‬​‫‏​‬‬‬‍‭‌​​‪‮(System.Windows.Forms.Form) ldloc.0 <null> ldc.i4 1256267674 mul <null> ldc.i4 837282822 xor <null> br.s IL_0006: ldc.i4 -478737954 nop <null> ldloc.0 <null> ldc.i4 241164259 mul <null> ldc.i4 -163157807 xor <null> br.s IL_0006: ldc.i4 -478737954 ret <null>

eef01da8c18de3fc7869717f93721038 (1.16 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ClipboardAnalyzer.MainForm.resources
ClipboardAnalyzer.Properties.Resources.resources
Teacher
[NBF]root.Data
kzud
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙