Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: cc79c483bd82e767f895902437d25710
Size: 690.69 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cc79c483bd82e767f895902437d25710
Sha1 ec891537902cfc46dfd4c23f523fb0cfd0bfb729
Sha256 392ec2e0db217dc665b13c2e73b00d0ca2dc3b7f8a47eedf9a715d613e57a464
Sha384 ceafcc8d217d4b3f66f7f858f5c21782b9597fb0c62fd627b2a807aa314f8cb44582a5dab1e5d445e8c3a8281649abe3
Sha512 5f74048088bc6d886e059b7b77ed18cf76ab3b6fa7c5035b7ae068384c3524f2747b92a4eb4b00e36d35409a390f3c41375f4237806bc57ba13386abfcde4ad2
SSDeep 12288:0aqojL4ep+9keRK6AKefTVYWHDqDBY7edfuMHPIjk1Z9D9QbOH1MCXRra94fiW/v:lqL9kegHDqDVJvIjINqbEBRzfiW/v
TLSH 98E4220031079603C872ABF66A61E0F4ABF55E9EB913DB578FE97E8B363E3114941253
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
PatternGenerator.Forms.MainForm.resources
PatternGenerator.Properties.Resources.resources
crc
[NBF]root.Data
jzBq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: agbn.pdb
Module Name
agbn.exe
Full Name
agbn.exe
EntryPoint
System.Void PatternGenerator.Program::Main()
Scope Name
agbn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
agbn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
84
Main Method
System.Void PatternGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PatternGenerator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙