Suspicious
Suspect

bb80b31e43893a35fabbdca00c3fd55e

PE Executable
MD5: bb80b31e43893a35fabbdca00c3fd55e
Size: 1.26 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 bb80b31e43893a35fabbdca00c3fd55e
Sha1 ea709516603279a6513ab58ae93ce220f0f0210e
Sha256 ae1a58b73c14de3d0d4af02ac0c136a4e804ed1a911de386fa40208672611309
Sha384 61ad40c1c503983ba561d5598f1eb430569927d87c6361566c0f7546f570cad8cd4df397bbba91343785264490d657d6
Sha512 fbd0a9acf738d9774c37673dc0c5b5a895a6ecd35661bccd5a8f2fccd56c09a4ed38eb679921e381129b27b8a2ac592109254e8cda9415ff677634b59e6e4c3f
SSDeep 24576:6xN6pbVwFbESb7mw/7T5Xald1sWNUcuNJPEfL0I++XpUXLlqhF:D1VcbxPms7TJqsWV8dEwW5U7l
TLSH 57452208725AD60BC92227391E70F2B927BF1DE9B811D2169FDDFCCB7A62B459C041D2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SmartCityManager.MainCityDashboard.resources
$this.Icon
[NBF]root.IconData
Fec
[NBF]root.Data
SmartCityManager.PowerGridControlRoom.resources
SmartCityManager.Properties.Resources.resources
eOsx
[NBF]root.Data
[NBF]root.Data-preview.png
SmartCityManager.Z.resources
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\WwiQtFruAz\src\obj\Debug\xLmF.pdb
Module Name
xLmF.exe
Full Name
xLmF.exe
EntryPoint
System.Void SmartCityManager.Program::Main()
Scope Name
xLmF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xLmF
Assembly Version
9.4.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
93
Main Method
System.Void SmartCityManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartCityManager.MainCityDashboard::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SmartCityManager.MainCityDashboard.resources
$this.Icon
[NBF]root.IconData
Fec
[NBF]root.Data
SmartCityManager.PowerGridControlRoom.resources
SmartCityManager.Properties.Resources.resources
eOsx
[NBF]root.Data
[NBF]root.Data-preview.png
SmartCityManager.Z.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙