Suspicious
Suspect

4128b578cfee06b281d580844fd5872f

PE Executable
MD5: 4128b578cfee06b281d580844fd5872f
Size: 1.2 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4128b578cfee06b281d580844fd5872f
Sha1 e3b93e6c2a7964ab53cdb514f19a9489dc4383b2
Sha256 7a39334c50e0ccb49d2ea85d615e2eef259a7232f36c4803c2d853b64639b6fa
Sha384 1b658ff848f709640138647e3ecb1af7390e4109a26f89bfb823b2ad1492b4eaf0f8638b7619bc0f14fe313a475b88cb
Sha512 c669233702d7578d3354f81fb5cf791bf17f0807786ae80f9b0a4450b045a8eacd4a9c4950ef17be525aae44be2094264725860053c8fe47b014c04f656c81d3
SSDeep 24576:jV/Nfva3P3F9OlGRy/j4fpmir78fLnrdwgaoyHO:zfva3PjOlz/jCkiHQWH
TLSH 794512602340E512D68467385AB0F3BA23F41DE9B801D342AFEDBDEFB926F114D58693
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
CyberNOC.MainNocForm.resources
$this.Icon
[NBF]root.IconData
Sides
[NBF]root.Data
CyberNOC.IdsRuleManagerForm.resources
CyberNOC.Properties.Resources.resources
HXHI
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ETlzvpnhwY\src\obj\Debug\JtGN.pdb
Module Name
JtGN.exe
Full Name
JtGN.exe
EntryPoint
System.Void CyberNOC.Program::Main()
Scope Name
JtGN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JtGN
Assembly Version
8.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
198
Main Method
System.Void CyberNOC.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CyberNOC.MainNocForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
CyberNOC.MainNocForm.resources
$this.Icon
[NBF]root.IconData
Sides
[NBF]root.Data
CyberNOC.IdsRuleManagerForm.resources
CyberNOC.Properties.Resources.resources
HXHI
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙