Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: ba0eeaf51f1f84a3d7b046608401c602
Size: 977.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ba0eeaf51f1f84a3d7b046608401c602
Sha1 bf9309f3efb5da2901adc70b25b6292c18a09891
Sha256 6fd471d3b5a60eb2827287c5b805a12d8e4147c5c2ce85585b3e2748a10e6226
Sha384 6fb78fd1a369a88330c60cf18c7b66fffbd39d45ef5316057b2c6ebe27f3a4bab65a442ed29a0b8b2064beca9bc07042
Sha512 1fc2525a910c90ecca265ce59917e7145e027d507392eff18ef2683e08c4c309820b30ba8c931da31fafcf5ec0ce968db26f8c0866a00a5ef8478e66615bab3e
SSDeep 24576:tp3hDfdUMHqIvApuI9h2L6a6xT+fLa1auKJ4KgrocNinY:T3hjuMHFvAl9a6aMILaauXRr1InY
TLSH 8E25236102A8C942CA39ABB10632D33627776FCAEB26D21A9FE5DC973841BF15D50347
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NotepadPlus.Properties.Resources.resources
DOLH
[NBF]root.Data
[NBF]root.Data-preview.png
PIP
[NBF]root.Data
grass
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile_2
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
Agfi.exe
Full Name
Agfi.exe
EntryPoint
System.Void NotepadPlus.Program::Main(System.String[])
Scope Name
Agfi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Agfi
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
203
Main Method
System.Void NotepadPlus.Program::Main(System.String[])
Main IL Instruction Count
52
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NotepadPlus.MainForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0060: ldloc.0
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
stloc.2 <null>
ldloc.2 <null>
call System.Boolean System.IO.File::Exists(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_005F: nop
nop <null>
nop <null>
ldloc.0 <null>
ldloc.2 <null>
callvirt System.Void NotepadPlus.MainForm::OpenFile(System.String)
nop <null>
nop <null>
leave.s IL_005E: nop
stloc.s ex
nop <null>
ldstr Error opening file: 
ldloc.s ex
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr NotepadPlus
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_005E: nop
nop <null>
nop <null>
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Agfi.exe
Full Name
Agfi.exe
EntryPoint
System.Void NotepadPlus.Program::Main(System.String[])
Scope Name
Agfi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Agfi
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
203
Main Method
System.Void NotepadPlus.Program::Main(System.String[])
Main IL Instruction Count
52
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NotepadPlus.MainForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0060: ldloc.0
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
stloc.2 <null>
ldloc.2 <null>
call System.Boolean System.IO.File::Exists(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_005F: nop
nop <null>
nop <null>
ldloc.0 <null>
ldloc.2 <null>
callvirt System.Void NotepadPlus.MainForm::OpenFile(System.String)
nop <null>
nop <null>
leave.s IL_005E: nop
stloc.s ex
nop <null>
ldstr Error opening file: 
ldloc.s ex
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr NotepadPlus
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_005E: nop
nop <null>
nop <null>
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
Aghuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙