Suspicious
Suspect

PE Executable
MD5: 469903f2d801f530b024a205e2a0ce13
Size: 872.96 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 469903f2d801f530b024a205e2a0ce13
Sha1 dc71e192518809cdfb3b6008de978821ce4150ae
Sha256 4ae6b4139407e03c9d0d67b1992ebd2db0000b4e261e0f18925a8fd72d99ffc5
Sha384 1e439f6adba3159cc6734f764ba61e6e925e532c270a6075f3a39c74884b08b6b51e2e1f5fe2086c1dc08d305f57212b
Sha512 45fa536a1c3109f5ac91a2252956fda06473275a1c06dc03077b2bf850cea59b7e37ebbcdca4e1f5556e2a1b288d56190c0448f597e31d9228c03b4d8dcca075
SSDeep 24576:R54jGYPbvXeTbTvr8PhWsJpDldagwVPu:D4jGYPbvXeTbbrpsJpJwgw
TLSH A605D11172A5AF42C5BD03F82161E77107F36DAFA429D35A1CC6ACEF3978B814E11A93
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EczaneOtomasyon.AnaMenu.resources
EczaneOtomasyon.Hakkinda.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.GenelMenu.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.Properties.Resources.resources
jj
[NBF]root.Data
wSnP
[NBF]root.Data
[NBF]root.Data-preview.png
EczaneOtomasyon.SaglikArsiv.resources
ımageList1.TrayLocation
Name Value
Module Name
igwt.exe
Full Name
igwt.exe
EntryPoint
System.Void EczaneOtomasyon.Program::Main()
Scope Name
igwt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
igwt
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1124
Main Method
System.Void EczaneOtomasyon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EczaneOtomasyon.GenelMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
igwt.exe
Full Name
igwt.exe
EntryPoint
System.Void EczaneOtomasyon.Program::Main()
Scope Name
igwt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
igwt
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1124
Main Method
System.Void EczaneOtomasyon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EczaneOtomasyon.GenelMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
ighuhuhuhu
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EczaneOtomasyon.AnaMenu.resources
EczaneOtomasyon.Hakkinda.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.GenelMenu.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.Properties.Resources.resources
jj
[NBF]root.Data
wSnP
[NBF]root.Data
[NBF]root.Data-preview.png
EczaneOtomasyon.SaglikArsiv.resources
ımageList1.TrayLocation
No malware configuration was found at this point.
PDB Path PATH
ighuhuhuhu
469903f2d801f530b024a205e2a0ce13
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
469903f2d801f530b024a205e2a0ce13
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
469903f2d801f530b024a205e2a0ce13
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙