d17cf2f47d925b55d6cfc3f17a864926b0ebbbd733840729c19ff3e71325fbc0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Mar-10 13:29:51
Comments
CompanyName Microsoft
FileDescription Laptop Battery Analyzer
FileVersion 3.3.0.0
InternalName NLBA_LaptopBatteryAnalyzer.exe
LegalCopyright Copyright © Microsoft 2015
LegalTrademarks
OriginalFilename NLBA_LaptopBatteryAnalyzer.exe
ProductName Laptop Battery Analyzer
ProductVersion 3.3.0.0
Assembly Version 3.3.0.0

Plugin Output

Suspicious Unusual section name found: K\x092\x0b3fy:
Section K\x092\x0b3fy: is both writable and executable.
Unusual section name found:
Malicious VirusTotal score: 10/59 (Scanned on 2026-04-09 04:07:20) CrowdStrike: win/malicious_confidence_100% (D)
Cylance: Unsafe
DeepInstinct: MALICIOUS
Elastic: malicious (moderate confidence)
Fortinet: PossibleThreat
Gridinsoft: Trojan.Heur!.03033281
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.moderate.ml.score
TrellixENS: Artemis!EEDC4D21C094

Hashes

MD5 eedc4d21c09419c37a8df6a39035e40a
SHA1 74926f2e4f76a8e27c30687903223541eda7ef5f
SHA256 d17cf2f47d925b55d6cfc3f17a864926b0ebbbd733840729c19ff3e71325fbc0
SHA3 44c2a74128f4fe0143e4ba05f7e4c892d1ceb93215e3a95f13511d2ca790e073
SSDeep 49152:zn45ykp1NzyUuFA9Y9gKHZEXrkNeC/E6l+O2mmVAbvL3i80M8pVtFtF3xRhks9k:zn6Jp1NzyPAI5EoEK+O2Ybb/0Thnis
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2026-Mar-10 13:29:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 8.0
SizeOfCode 0x38b800
SizeOfInitializedData 0x27cc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0060C00A (Section: )
BaseOfCode 0x27c000
BaseOfData 0x2000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x610000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

K\x092\x0b3fy:

MD5 ace5e4b076f37019a244892ba74cdb2a
SHA1 e224bc374c3cd7b0f926e7e33971ed3831a0076a
SHA256 6067604b948c1c462e7e5781b278827ebcb0b1f41aa82930878222a894e9a5ba
SHA3 df08fbb9e0ad3aa509da4a74a6f162f270d24eb8d16be579f8a2dae9729dfafb
VirtualSize 0x279ce8
VirtualAddress 0x2000
SizeOfRawData 0x279e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99994

.text

MD5 ad23002b445b242a76f19f8364e3cd2a
SHA1 4015ccb9e2e0c5156ee1aef543a5806f0f19e000
SHA256 18ec2ddbf343894298616515dfc6d2acf1e6d787946e28773829bf30d58ea38f
SHA3 7ff07f3e806a6e26f5a1df12fa5bdc85d3395dd5001a4e9012fa248f5e6004d2
VirtualSize 0x38b570
VirtualAddress 0x27c000
SizeOfRawData 0x38b600
PointerToRawData 0x27a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.87584

.rsrc

MD5 91bf2a9abdc589300de975dea20c2b37
SHA1 a97e9770fdd995cc29bb6a223157cca4df717905
SHA256 971daa4621d1e9b21411640a3b4b3a539c2b077102da766227d0fce8921f4554
SHA3 40e8eb88c7c84795209042cfdbcff8abae02777c7345a39dc8bbfbe746d12115
VirtualSize 0x2a64
VirtualAddress 0x608000
SizeOfRawData 0x2c00
PointerToRawData 0x605800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.11835

Section_4

MD5 8102c95e52336b87d55e236bebd1678f
SHA1 94641a3b6281c0d30fecbdf6835e0da21d936582
SHA256 4e2e268ffae25ccc80c78528543fe87bfbd489931d38e3f73665bd4689f5a60a
SHA3 ce3fab01c9fb492d82ba6585eac9f2db5e27df86c243e575badf0640be64f897
VirtualSize 0x10
VirtualAddress 0x60c000
SizeOfRawData 0x200
PointerToRawData 0x608400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 0.142636

.reloc

MD5 d259261914d60b81981ec80574fe73ab
SHA1 aebc904fefed7fa92da16b8eb9fa2f12cd4f54e3
SHA256 7aca1801ee3f01c6c2590439fcb7e275dc1738e8a553f9b5ca97783cb867126f
SHA3 169242f0a2ac41e67150691880bb74a34cd8c7f2643463ad735a6723b552a234
VirtualSize 0xc
VirtualAddress 0x60e000
SizeOfRawData 0x200
PointerToRawData 0x608600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0980042

Imports

mscoree.dll _CorExeMain

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.0994
MD5 7b3a976bf3695eb0cbcb5b7c916c5121
SHA1 77277923c0f80ae75c5b815a1098670c39a675b1
SHA256 a7ad9cd69b857a547222f23f0a5975b903e9cc5fd0b44a5cac7f547225817724
SHA3 9001f05f1a0de0c676820c6b4bad12979e76319fb604ed5cdab13881793bc58f

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 6da8e7d5ae1d5d15e0230a67a7c16c6d
SHA1 678db52cbe5d617c33c6269bfd4b6d8d1a17f956
SHA256 6eb54801f91b6d8effccbfaefe6b2d7705a274a75940e6226e24e0d4ec58c396
SHA3 994fc217c7b8bc8008ac262ff58044403206de6eceafd424d4640ecad395eb2f

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36262
MD5 a3abe9c0a6054cd23b4de0b98301ed71
SHA1 8829b939d01c8618ebc49641ffe8b4062d0e14f8
SHA256 c954e1ca22918db0c191f5b20e738d5091684b419f3835f1046acddb3c327474
SHA3 caa8e0316a4d8abbbc8f7b263dc5eb993b8a79c2df8490020f27cd3c474b326c

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.3.0.0
ProductVersion 3.3.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName Microsoft
FileDescription Laptop Battery Analyzer
FileVersion (#2) 3.3.0.0
InternalName NLBA_LaptopBatteryAnalyzer.exe
LegalCopyright Copyright © Microsoft 2015
LegalTrademarks
OriginalFilename NLBA_LaptopBatteryAnalyzer.exe
ProductName Laptop Battery Analyzer
ProductVersion (#2) 3.3.0.0
Assembly Version 3.3.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.