Suspicious
Suspect

41d6f105d71bc1c3db6c50191bcff83b

PE Executable
MD5: 41d6f105d71bc1c3db6c50191bcff83b
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 41d6f105d71bc1c3db6c50191bcff83b
Sha1 bf64d18f70633b54f9e62d054e6058c5c3a9ed69
Sha256 cb8416d5916dd7a960c8b243fb5fb893920b9ca5dff0f2f1a84688fa5c49edd4
Sha384 9a2b5431f753e0ed091b4672ec79dc691e175f04f592dd4d764778282a934cdb3b0173b0f665d8b00b5f0ce8205be329
Sha512 7d8c8dcdcdbd420940bad56460d1dd6f0d8fbf37d26c29e5ebba966e2df73152d580c8292cc9c05c9b993f8de3160031a219f054ae74f922cbc26e9dd4eccd8a
SSDeep 24576:2VvWLgIbexjy6iwzsEdZD1xJWLfWnSRebnb0UCLSkQCtK8:MvWLgLxZi8siZXKWnSR4bUekQCt3
TLSH 5F25E01033A69D53C47D8AF50A13D23097F64F5E6139D2DA9DE2BCFBB5E5B442820A83
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PharmacyProject.FrmDoktorHastaEkle.resources
button2.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmDoktorRecete.resources
PharmacyProject.FrmEczaneGiris.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmEczaneAna.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button10.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button3.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button4.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button5.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button6.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button7.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button9.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmEczaneRecete.resources
$this.Icon
[NBF]root.IconData
PharmacyProject.Properties.Resources.resources
mYbm
[NBF]root.Data
[NBF]root.Data-preview.png
nsh
[NBF]root.Data
Name Value
Module Name
lTsw.exe
Full Name
lTsw.exe
EntryPoint
System.Void PharmacyProject.Program::Main()
Scope Name
lTsw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lTsw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1139
Main Method
System.Void PharmacyProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void PharmacyProject.FrmAnaGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
lTsw.exe
Full Name
lTsw.exe
EntryPoint
System.Void PharmacyProject.Program::Main()
Scope Name
lTsw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lTsw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1139
Main Method
System.Void PharmacyProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void PharmacyProject.FrmAnaGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
lThuhuhuhu
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PharmacyProject.FrmDoktorHastaEkle.resources
button2.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmDoktorRecete.resources
PharmacyProject.FrmEczaneGiris.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmEczaneAna.resources
btnLogin.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button10.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button3.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button4.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button5.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button6.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button7.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button9.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PharmacyProject.FrmEczaneRecete.resources
$this.Icon
[NBF]root.IconData
PharmacyProject.Properties.Resources.resources
mYbm
[NBF]root.Data
[NBF]root.Data-preview.png
nsh
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
lThuhuhuhu
41d6f105d71bc1c3db6c50191bcff83b
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
41d6f105d71bc1c3db6c50191bcff83b
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
41d6f105d71bc1c3db6c50191bcff83b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙