Suspicious
Suspect

b088bd26f12a8cfdae525500ebc02838

PE Executable
|
MD5: b088bd26f12a8cfdae525500ebc02838
|
Size: 995.84 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
b088bd26f12a8cfdae525500ebc02838
Sha1
4af63f914fd84964656444ee708ef588ec322239
Sha256
aa7130af56cb7b9d0cc21651e5032fd8a0a002222e1338f7c05a54437fa023b3
Sha384
c3de2e730fe4f7ace303bf9ca40df5cce493fffa09fb2fd4f19d4a28a0cc5fbf94cf357b8721e37a5709909c7537acf7
Sha512
3b69c6b6c65e250e92cae10828398bae63ef8e4da3745e1fcf832e09315963752747e2da627a4ee41c26c1327887976928e72072759892497ba17df15b665b6e
SSDeep
12288:lGGLjZm3qylDrlP8snalrA2TqTuuhYkSg9UiqHqbRSX1dbum7owJf2b1AHS8PIyw:MG+fbPmlkMqSWBU/KbR47buUQ0IyUf
TLSH
A425124423AAEE16D4B62FF00970D3B413B67E09B812D30B9EF66DEB75787805981393

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
CKNc
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: nFKX.pdb

Module Name

nFKX.exe

Full Name

nFKX.exe

EntryPoint

System.Void BaselineTool.Program::Main()

Scope Name

nFKX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

nFKX

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

346

Main Method

System.Void BaselineTool.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void BaselineTool.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

nFKX.exe

Full Name

nFKX.exe

EntryPoint

System.Void BaselineTool.Program::Main()

Scope Name

nFKX.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

nFKX

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

346

Main Method

System.Void BaselineTool.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void BaselineTool.Forms.MainForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

b088bd26f12a8cfdae525500ebc02838 (995.84 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
CKNc
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙