Suspicious
Suspect

fb32f7acd3f3386c76f5a4df39667040

PE Executable
|
MD5: fb32f7acd3f3386c76f5a4df39667040
|
Size: 644.61 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
fb32f7acd3f3386c76f5a4df39667040
Sha1
0be8d989d0dbc44c838f16dd2a948582ffdb98b8
Sha256
6aeae35043c9ba97b7ef2fefb3a49943431eac600666e20614f09e5783328a50
Sha384
bf6971847a15b42ac90c2a9fad9f24e39bfe9fa7ae3e569f1d9916db81aad88520026a43ef59199c200a8283c99c3de4
Sha512
0b13b08147039f0ecae3b185c4a60f7534e14c4a8d2140e44ae92ab835809666f9339bb8b4103c4ce7d8cee41290eabaf936e03b04f2e8f30584dc36cb20c85a
SSDeep
12288:Ke3YXOpUjuTtYUltsiykrGMguXrvFfDqqCUf6JggA7JH62j7TAjFtbwWAZMeS:Ke3YXyJZlin2GMguXrvxNCo6JeH6
TLSH
8CD4CE8C36D5F8DEC847C5704DA0FD74A2206D6A93068D138EE72C9FB91D947AE341AE

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
JFzp
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

cDqw.exe

Full Name

cDqw.exe

EntryPoint

System.Void WindowsFormsCSharpProject.Program::Main()

Scope Name

cDqw.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

cDqw

Assembly Version

6.2.4.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

143

Main Method

System.Void WindowsFormsCSharpProject.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void WindowsFormsCSharpProject.Program::‬‬‮‪‫‌‎‍‫‬‬‍‭‪‌‎‭‪‫‫‭‫‪‍‭​‫‬‪‮() ldc.i4.0 <null> call System.Void WindowsFormsCSharpProject.Program::‏‭‫‏‭‮‌‬‌‌‪‌‭‫‮‏‌‎‌‪‫‬‫‭‬‎‮(System.Boolean) newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor() call System.Void WindowsFormsCSharpProject.Program::‪‪‮‪‍‎‮‎‫‬‎‍‫‏‌‪‎‎‌‭‪‪​‭‮(System.Windows.Forms.Form) ret <null>

Module Name

cDqw.exe

Full Name

cDqw.exe

EntryPoint

System.Void WindowsFormsCSharpProject.Program::Main()

Scope Name

cDqw.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

cDqw

Assembly Version

6.2.4.2

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

143

Main Method

System.Void WindowsFormsCSharpProject.Program::Main()

Main IL Instruction Count

6

Main IL

call System.Void WindowsFormsCSharpProject.Program::‬‬‮‪‫‌‎‍‫‬‬‍‭‪‌‎‭‪‫‫‭‫‪‍‭​‫‬‪‮() ldc.i4.0 <null> call System.Void WindowsFormsCSharpProject.Program::‏‭‫‏‭‮‌‬‌‌‪‌‭‫‮‏‌‎‌‪‫‬‫‭‬‎‮(System.Boolean) newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor() call System.Void WindowsFormsCSharpProject.Program::‪‪‮‪‍‎‮‎‫‬‎‍‫‏‌‪‎‎‌‭‪‪​‭‮(System.Windows.Forms.Form) ret <null>

fb32f7acd3f3386c76f5a4df39667040 (644.61 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙