Suspicious
Suspect

facff72b6a876d605b1854be16f21d44

PE Executable
|
MD5: facff72b6a876d605b1854be16f21d44
|
Size: 1.63 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
facff72b6a876d605b1854be16f21d44
Sha1
2df125d457121e46323ab36f5a60d3aa6ad48972
Sha256
e87df996786ff1613b8550abf66de6456faaf7e1a26e9217cd17a2f5a6caad50
Sha384
57c56cff5267e470b16df722d0f18a76ca0c6f2eb102fcee947ee2b2376de77ec9654f59dcf410275ea2cc446a046e71
Sha512
d67c16ad80397c1fff6dd96988e192dc681403e444e0823dd6a64c1c9c3a2b09c3162661722bd13f922b4979887c2b0a3e42cdcae7de9c8ff203426940f8e03c
SSDeep
49152:b8t85ftfAu4+hgfAxPOxJvROaYR86unXjkv:au4+AAGbvROaYyFnA
TLSH
4375F119E7E805E9E1FBD678C8224506C772F80A0B31EB8F079959D91F337909D39B22

PeID

Microsoft Visual C++ v6.0 DLL
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0002
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.pdata
.idata
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\defen\Desktop\xrddior\obj\Release\net8.0-windows\keshxrd.pdb

Module Name

keshxrd.dll

Full Name

keshxrd.dll

Scope Name

keshxrd.dll

Scope Type

ModuleDef

Kind

Dll

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

keshxrd

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETCoreApp,Version=v8.0

Total Strings

931

Main Method

Not found or no body

facff72b6a876d605b1854be16f21d44 (1.63 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙