Suspicious
Suspect

fbab91fae2e0cae22e6024d189e4a3e5

PE Executable
|
MD5: fbab91fae2e0cae22e6024d189e4a3e5
|
Size: 16.04 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
fbab91fae2e0cae22e6024d189e4a3e5
Sha1
4d079255411ad14f5b44c9cba26a4a7f779095ed
Sha256
e89cb454b197eb77825d7f6ad2d6ce359c2adf004f6bed4b15ce7988a12ff6d6
Sha384
84ba702b48ced80cced322bcd7a1c80bddd323fc5d0a2540577539eed0d48f1a1cb0edaaf6e22835e4825de4b4d6e080
Sha512
92ef3f2251559af97a88d589ec737897bf52d0aa14ad04876b8a95fcc7357929e3531a39fc9ed15087c7430b60354c9186b107d6f9a2d13b3ea3e5c826c5ae48
SSDeep
98304:8xclcbZ8QX2MG4dfNgi9BbBAlFNq7XG6gLiHn6SvW6/2tsRRElSMreHM7JGmbJMI:NlmZn9BClXq7W6gLiHn/uG2yElSzH4J
TLSH
79F6F52025D9AB03FD7ADFBD99CC76510F79B2913723EA384B5209E90ED1B18C8435A7

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual C++ v6.0 DLL
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
pays.Properties.Resources.resources
PD
ZvV
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Debug\main\obj\Debug\broad609.pdb

Module Name

broad609.exe

Full Name

broad609.exe

EntryPoint

System.Void pays.Program::Main()

Scope Name

broad609.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

broad609

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5.2

Total Strings

112533

Main Method

System.Void pays.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void pays.inconscient1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

broad609.exe

Full Name

broad609.exe

EntryPoint

System.Void pays.Program::Main()

Scope Name

broad609.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

broad609

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5.2

Total Strings

112533

Main Method

System.Void pays.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void pays.inconscient1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

fbab91fae2e0cae22e6024d189e4a3e5 (16.04 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙