Suspicious
Suspect

fb5830e3ea12e398db4fe1c57defc780

PE Executable
|
MD5: fb5830e3ea12e398db4fe1c57defc780
|
Size: 1.06 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
fb5830e3ea12e398db4fe1c57defc780
Sha1
6769355d985bf2f96c4970b054407a464fcf51bc
Sha256
66d0c643f5aa03a5b4303caf17c128e0dc030530f22da3af6ed927cbc9e4f1d6
Sha384
81e26710e5fbea17ddec460d781e18d44a887e7905e6119c50392f7787220b284f02030806ee6535401ecf1085da0e4e
Sha512
fc55e008dec7dfac4ca8f18521f288e9b7369be908ac7eb87d3797fc51976ffd10c94aba96bc61eaa58e3a5b14cd7aaecd392e70b46909283e3d4f70c853a844
SSDeep
12288:F1dbIAepSwPwriwNP9a4V+REPOi5+eyPtOzfiM159D7r9T8/yZYB9zU5D1CeN2Es:F19ZxwQidDZ+YUH9lHZ49zCT2/n
TLSH
A525020CFA76BA26CA8D0FBB9203211C84F79597E773F7675D9E09D20C25744885EA83

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

HsfBT.exe

Full Name

HsfBT.exe

EntryPoint

System.Void DiskAnalyzer.Program::Main()

Scope Name

HsfBT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

HsfBT

Assembly Version

1.0.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void DiskAnalyzer.Program::Main()

Main IL Instruction Count

21

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void DiskAnalyzer.Component1::Ⴗ() ldc.i4 273 ldc.i4 377 call System.Void DiskAnalyzer.FormStatistiques::Ⴅ(System.Char,System.Int32) ldc.i4.0 <null> ldc.i4 163 ldc.i4 226 call System.Void DiskAnalyzer.FormDoublons::Ⴅ(System.Boolean,System.Int16,System.Char) ldc.i4.3 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void DiskAnalyzer.FormPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void DiskAnalyzer.Program::Main() pop <null> ret <null>

Module Name

HsfBT.exe

Full Name

HsfBT.exe

EntryPoint

System.Void DiskAnalyzer.Program::Main()

Scope Name

HsfBT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

HsfBT

Assembly Version

1.0.2.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void DiskAnalyzer.Program::Main()

Main IL Instruction Count

21

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void DiskAnalyzer.Component1::Ⴗ() ldc.i4 273 ldc.i4 377 call System.Void DiskAnalyzer.FormStatistiques::Ⴅ(System.Char,System.Int32) ldc.i4.0 <null> ldc.i4 163 ldc.i4 226 call System.Void DiskAnalyzer.FormDoublons::Ⴅ(System.Boolean,System.Int16,System.Char) ldc.i4.3 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void DiskAnalyzer.FormPrincipal::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void DiskAnalyzer.Program::Main() pop <null> ret <null>

fb5830e3ea12e398db4fe1c57defc780 (1.06 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙