Suspicious
Suspect

PE Executable
MD5: b0730e315e4bf789befc36c1f7dffce7
Size: 709.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b0730e315e4bf789befc36c1f7dffce7
Sha1 5612fe1760e8244ca4309e2730c357c3837c70d7
Sha256 6307f6dcb83c11e69ad410e3d95d49834657fe2124f19c3c4e840d618bb53067
Sha384 eca31afb82dd420713aedc39c99434fc34b633996c130dd9de63d5c8179135f1923c131f9b52f00327f85adcdf1e2b31
Sha512 720a05b2ace9db6e6bcebfd39e322274303c9369f63583b105881d614c9bb46ed7fc4c05b9b95f192a1c04548cda9ef7dda5efe243ce87e22df619ed3ae8080c
SSDeep 12288:e0OWHSCGoamYlZmGCeb4WmaCMIDKal5mrJBgtr7miEGtXs:1xGTVl4GCmCMgKC5eMXmY
TLSH B0E412C82306EE17E0F10BF85DA1E3B457795D9EB401D7176BDDADE7782AA817880322
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HabitTracker.MainForm.resources
HabitTracker.Properties.Resources.resources
KS
[NBF]root.Data
LDPG
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: iibl.pdb
Module Name
iibl.exe
Full Name
iibl.exe
EntryPoint
System.Void HabitTracker.Program::Main()
Scope Name
iibl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iibl
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
110
Main Method
System.Void HabitTracker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HabitTracker.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HabitTracker.MainForm.resources
HabitTracker.Properties.Resources.resources
KS
[NBF]root.Data
LDPG
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙