Suspicious
Suspect

213210f1d2eb620d5dea124bba5c2cd1

PE Executable
MD5: 213210f1d2eb620d5dea124bba5c2cd1
Size: 760.83 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 213210f1d2eb620d5dea124bba5c2cd1
Sha1 e84c3933b7ca0eee93de2224abc08bdc38a95bb5
Sha256 cf504b21ac2e223e0cac9101b54ae1aa40fcd4c5fadcf5f3eacc7edd8aac819a
Sha384 c8af804cdc6b843a27897e2254c11324b43ab72369dbe6b1752530d00618436b346bb79b7692dfcb474bbc0558f6392f
Sha512 d9c0d023589c2338f7263f43d257066a1bad6ecaf2514e2f8875ae01f4a3577d662c0528645f331ed106974f527d1c07a0194713dbb556869a7da32b3292b8ad
SSDeep 12288:+qx1jZm3qZ2yQaM9AbwQQVRXTIteLA67wHZB7KZ+dPBoC3USn43kCwMQMz6A:vxkWI/9AbwbQeLACwHmZ+dPOaUS40YQW
TLSH F1F4F14523A9DD11D8F62FF00871E3B813BABE8D7920C3075EE6ACE77425B905A95393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
DeyF
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: NICi.pdb
Module Name
NICi.exe
Full Name
NICi.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
NICi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NICi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
NICi.exe
Full Name
NICi.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
NICi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NICi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
DeyF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙