Suspicious
Suspect

81982b8dd2d65e26ccc1db8a743747e4

PE Executable
|
MD5: 81982b8dd2d65e26ccc1db8a743747e4
|
Size: 566.27 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
81982b8dd2d65e26ccc1db8a743747e4
Sha1
36ea3f5f2c2498a961987e7c8c050fb8bc352cf4
Sha256
92d99c4f72097b0f2e956f4b0f7dcbb25cd8c7dccaf24be2c7120774c70d42f5
Sha384
792dc85fc2723390bbe308f647aa115d923c277d736707556dd3c254dc594bca63154aad949ad23bcec1cab42f926f5a
Sha512
726b5fb22a8083c151cb7ce36af60007089696e5ed11f297c1be6740dcead9672c567b1945561bade8b57132817c0fb28a2bef61c7ad7169d8567dd314ec4a39
SSDeep
12288:BrEUyAAdYIg1KXG1EiluSM3PNqyzHmetGswTn2V:9j1AOImlIge6n2V
TLSH
11C4CE2033A7D205D8660BB00C35D3F113B9BE9DBA14C71E6DED2E9FBD262535B116A2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StokTakip.BrandsManage.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Font
$this.Margin
btnCreateBrand.Location
btnCreateBrand.Size
btnDeleteBrand.Location
btnDeleteBrand.Size
groupBox1.Location
groupBox1.Size
lst_Brands.Dock
lst_Brands.Location
lst_Brands.Size
txtBrandName.Location
txtBrandName.Size
StokTakip.Form1.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Icon
[NBF]root.IconData
$this.Margin
$this.StartPosition
CTT
[NBF]root.Data
dilToolStripMenuItem.Font
dilToolStripMenuItem.Size
englishToolStripMenuItem.Size
markalarToolStripMenuItem.Size
menuStrip1.Size
menuStrip1.TrayLocation
satışToolStripMenuItem.Font
satışToolStripMenuItem.Size
tanımlarToolStripMenuItem.Size
StokTakip.PhoneCaseCreate.resources
$this.ClientSize
btn_AddStock.Location
btn_AddStock.Size
btn_Clear.ImeMode
btn_Clear.Location
btn_Clear.Size
btn_save.Location
btn_save.Size
cb_cases.Location
cb_cases.Size
cb_color.Location
label1.Location
label1.Size
label2.Location
label2.Size
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label7.Location
label7.Size
label7.TextAlign
lbl_info.Font
lbl_info.Location
lbl_info.Size
nm_price.Location
nm_price.Size
nm_qty.Location
nm_qtyAdd.Location
tabControl1.Location
tabControl1.Size
tabPage1.Location
tabPage1.Padding
tabPage1.Size
tb_name.Location
StokTakip.PhoneCaseManage.resources
StokTakip.PhoneCreate.resources
$this.ClientSize
btn_Clear.Location
btn_save.Location
btn_save.Size
cb_brand.Location
label1.Location
label1.Size
label2.Location
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label6.Location
nm_price.Location
tb_IMEI1.Location
tb_IMEI2.Location
tb_modelCode.Location
tb_name.Location
StokTakip.PhonesManage.resources
$this.ClientSize
btn_deletePhone.Location
btn_deletePhone.Size
btn_newPhone.Location
btn_newPhone.Size
filter_btn_search.Location
filter_btn_search.Size
filter_cb_brand.Size
filter_tb_modelcode.Location
filter_tb_modelcode.Size
grid_phones.Location
grid_phones.Size
StokTakip.Properties.Resources.resources
definitions
iconfinder_search_322497
[NBF]root.Data
[NBF]root.Data-preview.png
oniA
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\rRmCdSZjLp\src\obj\Debug\OHcF.pdb

Module Name

OHcF.exe

Full Name

OHcF.exe

EntryPoint

System.Void StokTakip.Program::Main()

Scope Name

OHcF.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

OHcF

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

255

Main Method

System.Void StokTakip.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void StokTakip.Ayar::GetLatestLanguage() nop <null> newobj System.Void StokTakip.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

81982b8dd2d65e26ccc1db8a743747e4 (566.27 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙