Suspicious
Suspect

bcb508367c78ebac45ab5af93c163c8e

PE Executable
MD5: bcb508367c78ebac45ab5af93c163c8e
Size: 674.82 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bcb508367c78ebac45ab5af93c163c8e
Sha1 b2637a64a2c1eac7a1f727d7cbfe99aaf816fe96
Sha256 ea7a7f6d060fe712bdd88ad09e4eddfbfd5d33fe9389c1b29374b3e913da4984
Sha384 64f3383ee01f9a00ce8226cdda7bc1f00fc8ca7655706cc460c015610e66b64f4c7098855e22075f622821e89964c03f
Sha512 07dba99223e5291730f52fffbfddd335a4dfdf5438033e22f206decd58b435d74a54f737234e85dd9ddbf5921a2813a74866471cb34b414821a78e4d59d80752
SSDeep 12288:hZA11Deo4zmMMKrUoheM5ATprRmPqfL43liK4d9azLDB2HkHw54bXKeaJikR:hZA1ko4zRfAohenTpRuqfkl4d9azLDB6
TLSH E8E402A863A89B53D6B54BF511B4D23017B47D5EB820E7088FDEBCDB7893B945E04A03
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedAlarm.Form1.resources
AdvancedAlarm.Properties.Resources.resources
Hyrkl
[NBF]root.Data
bWzb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xA1600 size 13832 bytes
Info
PDB Path: NbJH.pdb
Module Name
NbJH.exe
Full Name
NbJH.exe
EntryPoint
System.Void AdvancedAlarm.Program::Main()
Scope Name
NbJH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NbJH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
296
Main Method
System.Void AdvancedAlarm.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AdvancedAlarm.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
NbJH.exe
Full Name
NbJH.exe
EntryPoint
System.Void AdvancedAlarm.Program::Main()
Scope Name
NbJH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NbJH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
296
Main Method
System.Void AdvancedAlarm.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AdvancedAlarm.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedAlarm.Form1.resources
AdvancedAlarm.Properties.Resources.resources
Hyrkl
[NBF]root.Data
bWzb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙