×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2026-Apr-21 23:48:50
FileDescription
FileVersion
0.0.0.0
InternalName
AhkWpf_WPF_236706796_8316.exe
LegalCopyright
OriginalFilename
AhkWpf_WPF_236706796_8316.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious
No VirusTotal score.
This file has never been scanned on VirusTotal.
MD5
97f7b52d7881858b84f87506fb278f8a
SHA1
5fb471d25a263cbc479337e1a7cc15ee9036e28e
SHA256
677e2b37604e4b043d833bc77c743b8eb853b612f739adc09ba8117a8e1fa3bd
SHA3
85d6c76729e34667fd3dd00c95bcc309af5c11d46d83f2696a5bed804dc754b5
SSDeep
3072:zBdxwWTCaP0FOnzNBOgYLIkEbop3sgR0AAIQ3tOYaPG66MXGpsPmjIwPlqW7tOD:KqQ5
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
3
TimeDateStamp
2026-Apr-21 23:48:50
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Magic
PE32
LinkerVersion
11.0
SizeOfCode
0x1ce00
SizeOfInitializedData
0x800
SizeOfUninitializedData
0
AddressOfEntryPoint
0x0001ED3E (Section: .text)
BaseOfCode
0x2000
BaseOfData
0x20000
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
4.0
Win32VersionValue
0
SizeOfImage
0x24000
SizeOfHeaders
0x200
Checksum
0
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
d2f36d931eb2d298083163b7b8f4979d
SHA1
59d1cec86a86dfbc00f2fd9f1ab40647c4910818
SHA256
69d70a94005ca302c2c703ad763cf7cc64fd3e8b42491a16ab8e6dc118dd5dff
SHA3
95637b659390699da6fcc5060256653b48512590de533b42c5197c1c18a99bc0
VirtualSize
0x1cd44
VirtualAddress
0x2000
SizeOfRawData
0x1ce00
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
3.94757
MD5
361abea3c1024a95ccd75d261e7c8dfb
SHA1
c48560ede8e35d8addf52769e636dd5c16c8a4a9
SHA256
1475c56c970f0e95c7c4c48ec4e04fede3129900b3237743176accae13b767e0
SHA3
c9e3239c0bcfd45c921ef4721ff806d66c2ee98c99cfb78f332de5d9814ce4c0
VirtualSize
0x520
VirtualAddress
0x20000
SizeOfRawData
0x600
PointerToRawData
0x1d000
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy
3.91327
MD5
b7bdb97033a82465df61720a3a5fdc91
SHA1
532300542393b63725d128ee4c5e975c2838bf73
SHA256
1a0b50fa0e9024a134897c4bf48ee70f558e0b330f7688fead29bdc32b1fcfd3
SHA3
c46630c10e08a1add06048948edf3a5a6c012d74f1dd7befba1202673accbb7d
VirtualSize
0xc
VirtualAddress
0x22000
SizeOfRawData
0x200
PointerToRawData
0x1d600
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.10191
Type
RT_VERSION
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x28c
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
3.34395
MD5
e947276b063dfbcfe0fd71362ca8bafe
SHA1
c3898dfeaf21dcd5bc10c4f73c199b5bf3032cc0
SHA256
a86f7305b6dda8fcbc10ef2411e19ef369c5f0cdb632c9c9def45996517c8b9b
SHA3
e1ccc05582298bd9f85780e7dbd8d70c8da7d0aad662091909fe024dfe0341f8
Type
RT_MANIFEST
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x1ea
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
5.00112
MD5
a19a2658ba69030c6ac9d11fd7d7e3c1
SHA1
879dcf690e5bf1941b27cf13c8bcf72f8356c650
SHA256
c0085eb467d2fc9c9f395047e057183b3cd1503a4087d0db565161c13527a76f
SHA3
93cbaf236d2d3870c1052716416ddf1c34f21532e56dd70144e9a01efcd0ce34
Signature
0xfeef04bd
StructVersion
0x10000
FileVersion
0.0.0.0
ProductVersion
0.0.0.0
FileFlags
(EMPTY)
FileOs
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType
VFT_APP
Language
UNKNOWN
FileDescription
FileVersion (#2)
0.0.0.0
InternalName
AhkWpf_WPF_236706796_8316.exe
LegalCopyright
OriginalFilename
AhkWpf_WPF_236706796_8316.exe
ProductVersion (#2)
0.0.0.0
Assembly Version
0.0.0.0