Suspicious
Suspect

PE Executable
MD5: b25ccec179bdd3c5f8cba03fc36f0e17
Size: 729.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 b25ccec179bdd3c5f8cba03fc36f0e17
Sha1 c4107361d8367d63b5c6d4cc5edc90be3d1f1066
Sha256 aaa5b20a90d1f1755d39e6e228f8d4a4060d9da1451d9dd54a6e85fa2dd9ceef
Sha384 045b05387ebf927b6fafeaec67b22e76433b9e13fff188b470a706bb9b68cd41def9b9ed28e881d22a44aa2b7c63384f
Sha512 73c004c20f3a68fb176c9fc18975f013bae6342b747f32e638d3740a947d6be4c061b979c1526866fa5b663e3d83be5e040391e242fc8e86811c6e4e229cd1a1
SSDeep 12288:X1eW797h1f3qbgDeAt/3dSymmhzmEL4LhQpNSc9PoQkcywRtGBB7:FeWp7hlabgaAtvrgEmWpNScVSmtGP
TLSH 52F412505644C927C8EA17F04CB0F3B81AA85DCAF910D703EAEABED77D3171D66883A5
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
htta
[NBF]root.Data
jkIP
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: BEli.pdb
Module Name
BEli.exe
Full Name
BEli.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
BEli.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BEli
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
BEli.exe
Full Name
BEli.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
BEli.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BEli
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
htta
[NBF]root.Data
jkIP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙