Suspicious
Suspect

ff5b9d5d5cacf48c210ceb8cb34f5ef0

PE Executable
|
MD5: ff5b9d5d5cacf48c210ceb8cb34f5ef0
|
Size: 689.15 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
ff5b9d5d5cacf48c210ceb8cb34f5ef0
Sha1
9853f6e1559ca93d72dd034c93b663552c046182
Sha256
59aedd0ba303a510c3278eabc30b79e8ec3268d3e0b7ac28466d7caf5c6863aa
Sha384
54fca53b3b36f81201288040ef91ffd9f75eef80b0c8dbd635cee0e380c16193729c04d03fa6d5d927cc4e1faf640166
Sha512
3dfb1d6896f15c051175d92f3bbca24081aecfc6d11700974982944ce5f125ec7bda53814244ad20aa159ea07d79398caf08669a00ec1c0943aa4d7badaa30ed
SSDeep
12288:0Ozvk6qudjoeepEU7NU0A2+mlcMt4qo6lbrRy7Dv3YlsVPk7:JSpJZA2+WcMZxbkDv3hPk
TLSH
4DE4230FB64ADE67CE1E4B37C453520CD4FAC9E1B412F27E258225920E25F8CC5A7DA6

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

CuSi.exe

Full Name

CuSi.exe

EntryPoint

System.Void Carubbi.MetroLayoutEngine.MainC::Main()

Scope Name

CuSi.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

CuSi

Assembly Version

1.4.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void Carubbi.MetroLayoutEngine.MainC::Main()

Main IL Instruction Count

21

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴗ() ldc.i4 864 ldc.i4 795 call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴃ(System.Int32,System.Int16) ldc.i4.0 <null> ldc.i4 318 ldc.i4 277 call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴓ(System.Boolean,System.Int32,System.Int16) ldc.i4.1 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void Carubbi.MetroLayoutEngine.MainC::Main() pop <null> ret <null>

Module Name

CuSi.exe

Full Name

CuSi.exe

EntryPoint

System.Void Carubbi.MetroLayoutEngine.MainC::Main()

Scope Name

CuSi.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

CuSi

Assembly Version

1.4.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

2

Main Method

System.Void Carubbi.MetroLayoutEngine.MainC::Main()

Main IL Instruction Count

21

Main IL

ldc.i4.4 <null> stloc.1 <null> ldloc.1 <null> switch dnlib.DotNet.Emit.Instruction[] call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴗ() ldc.i4 864 ldc.i4 795 call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴃ(System.Int32,System.Int16) ldc.i4.0 <null> ldc.i4 318 ldc.i4 277 call System.Void Carubbi.MetroLayoutEngine.ConfirmDialog/Ⴍ::Ⴓ(System.Boolean,System.Int32,System.Int16) ldc.i4.1 <null> stloc.1 <null> br.s IL_0002: ldloc.1 newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> ldtoken System.Void Carubbi.MetroLayoutEngine.MainC::Main() pop <null> ret <null>

ff5b9d5d5cacf48c210ceb8cb34f5ef0 (689.15 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙