Suspicious
Suspect

baa6c5cf32cbff328e1a5dbfabd05aa2

PE Executable
MD5: baa6c5cf32cbff328e1a5dbfabd05aa2
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 baa6c5cf32cbff328e1a5dbfabd05aa2
Sha1 3c5970a546df797faef45dcda2babbec7576695a
Sha256 cddab0693d40c88f95f7a89fc82f8a243bfcd1cec58a04e02d316fac8b43e725
Sha384 763777c69a4698148c603325687453336be2cdb76accd3974f7d03b4599c74d6836e09d9c41c8d76934dc650b6c7297b
Sha512 0eb4e693daf757961802819dbb037306e6b2aeab5c0fecfd04950edf4529586213dada5b91bfa4796234de3af7a843a28098b6f18674b36a02a237be4d50dee6
SSDeep 24576:g3HUcEkSLCUaVsIlFZfMgSi62uYx+i1JrVsZZj:g3tEBCUU3ly/YMi1Je
TLSH C355222427E9DE22C4A62BF459B1D2B10378AD0CA422D3278FE57CEF79B9F151618353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
iJyilp
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
iVmZui.exe
Full Name
iVmZui.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
iVmZui.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iVmZui
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
iVmZui.exe
Full Name
iVmZui.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
iVmZui.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iVmZui
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
iJyilp
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙