Suspicious
Suspect

fe819152bb4b2924f7f5869986879e1c

PE Executable
|
MD5: fe819152bb4b2924f7f5869986879e1c
|
Size: 946.69 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
fe819152bb4b2924f7f5869986879e1c
Sha1
e9a1b75e638c5ab6d3090269f4fe99a3f9eda457
Sha256
a008bbcb7eed325eb375f6e8f3e74c72048e4d159f3b996490f73ad99b76b33e
Sha384
97ccd747b9b56e7b583a8e47d43d96398267cd60a42fa5187e14484e9d850a26063fd110facec82e3332d22a45dd5553
Sha512
bb39c0beb7e2cccfb024ad6402b35b0b5115899b25714f683e5208ffa40efcc265c6b49d5d89056cbe2141d25c4e01a6cc3819a6578798c404e5fb81224f436d
SSDeep
24576:5Jzfthl8Tpr3rtHKWncUQGe5g6ZWTe5oBm:5hthl0pbrd655g6ZB5X
TLSH
B51501546736CE02D4B547B718B2F5392FBE2D6AA821F2118ED53DDBBD72B024A40393

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
DAnS
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: iThv.pdb

Module Name

iThv.exe

Full Name

iThv.exe

EntryPoint

System.Void ModularExponentiation.Program::Main()

Scope Name

iThv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

iThv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

224

Main Method

System.Void ModularExponentiation.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ModularExponentiation.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

iThv.exe

Full Name

iThv.exe

EntryPoint

System.Void ModularExponentiation.Program::Main()

Scope Name

iThv.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

iThv

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

224

Main Method

System.Void ModularExponentiation.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void ModularExponentiation.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

fe819152bb4b2924f7f5869986879e1c (946.69 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
DAnS
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙