Suspicious
Suspect

46cc3df36f82bd6bba14a0059f1bf059

PE Executable
MD5: 46cc3df36f82bd6bba14a0059f1bf059
Size: 533.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 46cc3df36f82bd6bba14a0059f1bf059
Sha1 f69257899a7a3475141f118a5bb1ab608eb7b506
Sha256 fb8a925dd04fd2bcf0d95a93d39cbc4297647f22af997efedf07121356cbba29
Sha384 b1f272cf22e76c608ccf78085435907603ce3dc4b0d4be9f778875434bf5dd5f3d4fcf1fe55c700ad25bee9c4e159bf5
Sha512 b8810b9521a15521b337d87b468ebe1e335780b98562c414a98ab560d498b7c785c6b4649a8997792da2e69f34703536adb9670b2faa563f5de962af75c03ff7
SSDeep 12288:e1MoooooigooonkiHXkc2XdZISU21mwL1KEulykSGIZMCyVhK:2Moooooigooonb3QiQhL1Nu0kQZM9K
TLSH 24B4E1643629AC13E8BA66F008E5D2B853FC4DCEB420D3CE1EE66DD73EE57064601297
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hastane_Projesi.FrmBilgiDuzenle.resources
$this.Icon
[NBF]root.IconData
Hastane_Projesi.FrmDuyurular.resources
Hastane_Projesi.FrmGirisler.resources
Hastane_Projesi.FrmSekreterDetay.resources
Nerde
[NBF]root.Data
Hastane_Projesi.Properties.Resources.resources
IWUm
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\uEIkpKuLEP\src\obj\Debug\Hvav.pdb
Module Name
Hvav.exe
Full Name
Hvav.exe
EntryPoint
System.Void Hastane_Projesi.Program::Main()
Scope Name
Hvav.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hvav
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
464
Main Method
System.Void Hastane_Projesi.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Hastane_Projesi.FrmGirisler::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hastane_Projesi.FrmBilgiDuzenle.resources
$this.Icon
[NBF]root.IconData
Hastane_Projesi.FrmDuyurular.resources
Hastane_Projesi.FrmGirisler.resources
Hastane_Projesi.FrmSekreterDetay.resources
Nerde
[NBF]root.Data
Hastane_Projesi.Properties.Resources.resources
IWUm
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙