Suspect
PE Executable
MD5: ba0eeaf51f1f84a3d7b046608401c602
Size: 977.42 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | ba0eeaf51f1f84a3d7b046608401c602 |
| Sha1 | bf9309f3efb5da2901adc70b25b6292c18a09891 |
| Sha256 | 6fd471d3b5a60eb2827287c5b805a12d8e4147c5c2ce85585b3e2748a10e6226 |
| Sha384 | 6fb78fd1a369a88330c60cf18c7b66fffbd39d45ef5316057b2c6ebe27f3a4bab65a442ed29a0b8b2064beca9bc07042 |
| Sha512 | 1fc2525a910c90ecca265ce59917e7145e027d507392eff18ef2683e08c4c309820b30ba8c931da31fafcf5ec0ce968db26f8c0866a00a5ef8478e66615bab3e |
| SSDeep | 24576:tp3hDfdUMHqIvApuI9h2L6a6xT+fLa1auKJ4KgrocNinY:T3hjuMHFvAl9a6aMILaauXRr1InY |
| TLSH | 8E25236102A8C942CA39ABB10632D33627776FCAEB26D21A9FE5DC973841BF15D50347 |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
| Name | Value |
|---|---|
| Module Name | Agfi.exe |
| Full Name | Agfi.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | Agfi.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Agfi |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
| Module Name | Agfi.exe |
| Full Name | Agfi.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | Agfi.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Agfi |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
PDB Path
PATH
Aghuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential