×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2026-Feb-10 19:45:54
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious
No VirusTotal score.
This file has never been scanned on VirusTotal.
MD5
dc5b3f66e243a1262b1e99fd807e62ca
SHA1
842cabdb93b44093009668f184b02a909d8254c4
SHA256
2ee4fcf472b3802dee9bc2280b88cb5529f445525ef345be943490e74f49d7b7
SHA3
2bf3e1e785688846d32462f653c9281d06e086e8f961380f0b93050b2bcdd9b3
SSDeep
192:hCBxcRhBziDCxRERvTlR43VdVX9qqDv9W4q:Y2BzMCxRENTlR+/qqD
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
2
TimeDateStamp
2026-Feb-10 19:45:54
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Magic
PE32
LinkerVersion
48.0
SizeOfCode
0x1800
SizeOfInitializedData
0x200
SizeOfUninitializedData
0
AddressOfEntryPoint
0x0000372A (Section: .text)
BaseOfCode
0x2000
BaseOfData
0x4000
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
4.0
Win32VersionValue
0
SizeOfImage
0x6000
SizeOfHeaders
0x200
Checksum
0
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
50c3983b328f16a7d81fd4c13d574bbd
SHA1
04c52a3cce32841437e5072edb51919207f1df89
SHA256
8fb8d12e3d39b315711226b3d7b09bcac6e40e4e73ff9bdcbfa13da6787d5b76
SHA3
77b9cd2ed2146599550026fa523311c05cfce26a116631decd819d41d67f2130
VirtualSize
0x1730
VirtualAddress
0x2000
SizeOfRawData
0x1800
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
5.39593
MD5
02403277e884878e6387a0e2a0226a69
SHA1
4c497a570c56492059e29d0bab10d92d811e9224
SHA256
43f284b2207df8bd9b0df9051b7c2414d465b92ae7e74c9beb755b55ffb41dff
SHA3
b2f1c006094328abd9035dd4ae57ed270216ce52319b940abdd3510f7a83499e
VirtualSize
0xc
VirtualAddress
0x4000
SizeOfRawData
0x200
PointerToRawData
0x1a00
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.0815394