Suspicious
Suspect

318a6d31746ddf04e2665f1b41b96be2

PE Executable
MD5: 318a6d31746ddf04e2665f1b41b96be2
Size: 753.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 318a6d31746ddf04e2665f1b41b96be2
Sha1 93e959bc90183eb16e04b8f20fee0920601a2113
Sha256 dc822bf7d695ba868679506e564c997c5ff7c2ec8db8b7c8a4606a79a28a9ac3
Sha384 4ee81dfb311f49b3f5a854566fa846bbc20c21b4d08f4f016899e3e35143c74b934ad72ece1027af34f5ed0d275a90d9
Sha512 6c5658fea68de2e72c2738427854d02d37fe847ed36cb8b6596f9b8f04f74e54a022135324411e3b3942a2f6af80d3bbc04af9aa9fd60aea7877c814e2847265
SSDeep 12288:Z9yNjZm3q1gV7OPto/Hd+/NgXMrfmc6faqLZdfMDd+a/AMhPRtr1e:Hy8+AqP+/HdqNgWfAjnf6d+8dPrrM
TLSH FAF4011123AAEE05D5E61FF40871D3740779BE5AB921C30B9EF66DEB383578069903A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
nLyK
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ibhK.pdb
Module Name
ibhK.exe
Full Name
ibhK.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
ibhK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ibhK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ibhK.exe
Full Name
ibhK.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
ibhK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ibhK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
nLyK
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙