Suspicious
Suspect

1e178cfda97095b59122f9d0b5ee6af3

PE Executable
MD5: 1e178cfda97095b59122f9d0b5ee6af3
Size: 822.27 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1e178cfda97095b59122f9d0b5ee6af3
Sha1 cb323c30fd088fac6b47dbec49b735bb5e78d8a9
Sha256 de312dcd59a31066154401efdb6bccba79d20c4f4d9d926c6123ddcea9c2b3da
Sha384 4c1365169bca735d225e975c96ee9fd04f7442e640bd751180686498ae8d4ffbb334262f252a8b95beb7803b5b512922
Sha512 a55b66c8faba9fa17642c712290547ecb647b0a8467c0bf9ed1848adddd9dadad7b8bb94561a614c0ec546767daed53c74409d7e3d8ba9f94c8a318826604598
SSDeep 12288:nWNzduH3HU9CfLoCHPGObFGX3PXu+F2jQ/rvzBWmnSNW29/P3hhLXvDIo1SZ5YrA:X3HUc0wPfbM2+FBrKH3hhTv51KYy
TLSH 1A05F1142BDACED2D4660BF44C70F2B113286D4AB005DE2B8FE57CDB35A6B05263666F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
BQHAHX
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
hgnoCp.exe
Full Name
hgnoCp.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
hgnoCp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hgnoCp
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
hgnoCp.exe
Full Name
hgnoCp.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
hgnoCp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hgnoCp
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
BQHAHX
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙