Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 8b32fc9b8003ba21216772a076931764
Size: 1.26 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8b32fc9b8003ba21216772a076931764
Sha1 b6802d4fecdb1637bd2c38dcfcb080a26695ca6e
Sha256 982ea5afdf3816256c473b9df8136c96894ec8e1037ab02fdeb55caf65bbf3ce
Sha384 409762ebb8995a9f693479c7c47fee7b35485a5df99c98e8cf0f4fe3f202d3accd172c08579cdd9c30ea384fa3f5b6a2
Sha512 f92bf1154ccf4c29ad0eee3c5e2e931255d16466ede85faf4576765df0d91d59c54ad0ae12dda948b9e698499e0f9ad7c1a78dd059d8a161aab217b4736ba303
SSDeep 24576:r3H03ba8jwXvlcxSu5BLALK94NjgFp2M6vRgGtv0YM:j2al54BoNjIcWYM
TLSH 3845220533A5DE01D5A62FF008B0E3740775BE8DAA14D3465FF9ACEB747AB902669383
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
Ojki
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x130E00 size 13832 bytes
Info
PDB Path: seRc.pdb
Module Name
seRc.exe
Full Name
seRc.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
seRc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
seRc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
seRc.exe
Full Name
seRc.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
seRc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
seRc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙