Suspicious
Suspect

fb23ed1c71e91305c8222258cd22f3b0

PE Executable
|
MD5: fb23ed1c71e91305c8222258cd22f3b0
|
Size: 733.18 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
fb23ed1c71e91305c8222258cd22f3b0
Sha1
730b08d220e9d3947e1e9d90f8ed84ea398077d3
Sha256
8dfdf9c7b2657d5f27838a2ee023e77497bc31e87853983974db402852a28ebc
Sha384
4a8c9589992cd7ddc2229b59b8138bfe22c0c222f50512f4357d5f868fe5206c38f0888e8014a55c871db572894376f5
Sha512
e54dea355262b7e519fbea510cc15639a472002bd3c9c80859567a89e2d3ce3ead871d3868a2dca99979e262543aef8b1c16cdc64d8bd6e13d744b68e2888a5b
SSDeep
12288:JaQa3EDu/GC22PVKLl/1Ad6wiXM83fl97sb2vAIA7M2ubAndbWuJxSI/iTddpQx3:Q0Du/GClPANOd6hM89ybcLrb6db96Yio
TLSH
BEF422756618E603CE5117B046A1DBF3233A5EDDC821C30B95EEECDBBD0739826962D1

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
uviD
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
Informations
Name
Value
Module Name

SGqP.exe

Full Name

SGqP.exe

EntryPoint

System.Void PuhonRM.Program::Main()

Scope Name

SGqP.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGqP

Assembly Version

1.6.2010.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

107

Main Method

System.Void PuhonRM.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PuhonRM.ItemView::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

SGqP.exe

Full Name

SGqP.exe

EntryPoint

System.Void PuhonRM.Program::Main()

Scope Name

SGqP.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGqP

Assembly Version

1.6.2010.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

107

Main Method

System.Void PuhonRM.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PuhonRM.ItemView::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

6

Suspicious Type Names (1-2 chars)

0

fb23ed1c71e91305c8222258cd22f3b0 (733.18 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙