Suspicious
Suspect

fbcac38f851d6cb0718395382c854a80

PE Executable
MD5: fbcac38f851d6cb0718395382c854a80
Size: 503.81 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fbcac38f851d6cb0718395382c854a80
Sha1 0f08258eaba6ad30ddd6a06ee55006d0e8c192b1
Sha256 ce8bb22be29d0043943e2a2a0516d6138aae58dafcd9ad76236a4510e693d9f0
Sha384 adf1370427f37516c8344f99010d96eb9213abf4806be7f4c4aee760e8d50594d623c869761ed806144eee39f791da29
Sha512 bf5ee08f6c47a6b7af512049fd7069ad0e55f47e3231c1ce9345f74b67bc34ecfdcc1f6f95ff240e54f378a5b505ac9af59e2d44dd07195fbc99576d36476909
SSDeep 6144:E9LoQZkJEMP4a0hOSJ6e+4wmVY2tDA5U5t5ULWmhAWpRsSvV7lpJcupktbR8Zl0b:S1kyaXmi4wmts5U5t5UtVxE98Zl053h
TLSH F4B4015C2A0B9B03CDA153B04EA1F6B5533E1EADAD02E2525FD8BDDB7A63F044D11263
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AgatePrintingStation.ClientSolution.AddClientForm.resources
AgatePrintingStation.frmMain.resources
$this.Icon
[NBF]root.IconData
MN
[NBF]root.Data
AgatePrintingStation.Properties.Resources.resources
RmJz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ZQqa.exe
Full Name
ZQqa.exe
EntryPoint
System.Void AgatePrintingStation.Program::Main()
Scope Name
ZQqa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZQqa
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void AgatePrintingStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AgatePrintingStation.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ZQqa.exe
Full Name
ZQqa.exe
EntryPoint
System.Void AgatePrintingStation.Program::Main()
Scope Name
ZQqa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZQqa
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void AgatePrintingStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AgatePrintingStation.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AgatePrintingStation.ClientSolution.AddClientForm.resources
AgatePrintingStation.frmMain.resources
$this.Icon
[NBF]root.IconData
MN
[NBF]root.Data
AgatePrintingStation.Properties.Resources.resources
RmJz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙