Suspicious
Suspect

PE Executable
MD5: b8de9d41b3fe0fdaf1a2d6f5c4e4a2cb
Size: 726.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b8de9d41b3fe0fdaf1a2d6f5c4e4a2cb
Sha1 d56041da81d3f298064d3314a06173ddf2b04d6b
Sha256 5b287d4a2e0a8b69148ff5ac3f971e27de37f3332c4239c2d2b25762b855655d
Sha384 9b279a1a09e01d2f0eb3782078f92525ff6a1c3c6d24f93d0d858433cca0749beb9408fc615ee24f1da2f1a5d43fb6a8
Sha512 858fd6952cacc222a014967b736dedbc7953590432f186e58a740108ae4302afd776d0157baea0f5443fcf9d5ab45eadd6a4c04a4e16fdcec1c9da903fea815f
SSDeep 12288:QTlWjZm3qsDaC2+BzHVbWiMAuBTlIGsgOo0HymCxwMU42K5eA7ePn:slbFOR+5HpWiVuBpdsHo0S/ia5/7
TLSH 50F40145336ADE12D4F56BF00870E3780379BE8AB921C3069EE56CFB7474B9169907A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
vfOI
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: lzbN.pdb
Module Name
lzbN.exe
Full Name
lzbN.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
lzbN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lzbN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
lzbN.exe
Full Name
lzbN.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
lzbN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lzbN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
vfOI
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙