Suspicious
Suspect

PE Executable
MD5: fbbd633652647347551a2c65855edd60
Size: 714.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fbbd633652647347551a2c65855edd60
Sha1 668d09eba5557091f98a775ee7e7aed004d6dee1
Sha256 6842353066cfb2ade54cb7aa3b853da9fda7fe9dab2fa98395d1f41e5de5b015
Sha384 03dfc28c187d5f238d4b1fdc5cb92cc4328496e9bad234e60dabaf3c00d988fc464bde325647144b9849dc85201c9919
Sha512 01e53156f39ebfa1661ce67cc3b08d697fb7e36816d5b3b6d17f75d08064054fe366ff361b636ae263eabb58ccec0e994b1f98b4eb1d8d78d00390e4409de0d6
SSDeep 12288:xbEhjZm3qA5uFEcXPdzbXLkHPzVPpdr6q5BdSlizsbZMc8R3BBO8:BEohuF7/1nkH5PbV5nS6qvkR9
TLSH CAE40155236AEE02D4A66BF00870D3B407B6BE4EB920C307AEE56CFF7435B91A954353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
vLbx
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: cYVi.pdb
Module Name
cYVi.exe
Full Name
cYVi.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
cYVi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cYVi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
cYVi.exe
Full Name
cYVi.exe
EntryPoint
System.Void BaselineTool.Program::Main()
Scope Name
cYVi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cYVi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
346
Main Method
System.Void BaselineTool.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BaselineTool.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BaselineTool.Forms.MainForm.resources
BaselineTool.Properties.Resources.resources
AUDI
[NBF]root.Data
vLbx
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙