Suspicious
Suspect

fbe008f03e09206a6c64865232722956

PE Executable
|
MD5: fbe008f03e09206a6c64865232722956
|
Size: 752.64 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
fbe008f03e09206a6c64865232722956
Sha1
6bb1e2ca105a642d947d580af6e3698450f01d09
Sha256
0e222d955001ca2d7c51d16fbc43b7540941d36408663c53d178242c87b460b4
Sha384
2178069ab4e3110840ffb9fbf6ce3fe8a2825230fed07c7813f8b27df7a799fdcafdf4ce004320bc02b8cc0534e1e7e9
Sha512
341b32446dbfcf224d29cf7bd3fb3c617c8e0feba7a56471ccd291dda2c8596e31355ce38a90dd6ce8acc280af07031fc4e9bba1f53111cfb58be910c189adf2
SSDeep
12288:Apad7Ux3VYT8U0Srv/+kyhnp0Qc9BuDJnl+zrt0BlHoAnl8:ApO72KYU0wX+kuWQc9Bijct0BlHoG8
TLSH
D1F4DF1026249F03EA7A87F60511E03213F95E9DA56EE2555FC2BCDF387AF9059A0F23

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Login.resources
$this.Icon
QLDTDD_FPT.Mainform.resources
DF
menuStrip1.TrayLocation
QLDTDD_FPT.Properties.Resources.resources
qAyC
Informations
Name
Value
Module Name

eHJX.exe

Full Name

eHJX.exe

EntryPoint

System.Void QLDTDD_FPT.Program::Main()

Scope Name

eHJX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eHJX

Assembly Version

5.2.1024.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

998

Main Method

System.Void QLDTDD_FPT.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void QLDTDD_FPT.Mainform::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

eHJX.exe

Full Name

eHJX.exe

EntryPoint

System.Void QLDTDD_FPT.Program::Main()

Scope Name

eHJX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eHJX

Assembly Version

5.2.1024.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

998

Main Method

System.Void QLDTDD_FPT.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void QLDTDD_FPT.Mainform::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

18

Suspicious Type Names (1-2 chars)

0

fbe008f03e09206a6c64865232722956 (752.64 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙