Suspicious
Suspect

PE Executable
MD5: 8ff997f56afc367c83598bd9a403e71e
Size: 782.34 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8ff997f56afc367c83598bd9a403e71e
Sha1 6ba6096ca37a7b0bd9de6d681dbf277ac7ff6469
Sha256 20345515151dd9c4db1f9e97332aaaddc80ae9a2d6f75093e2701c5cc9e86dcf
Sha384 964c4b348f31243f0d3618b83bde6e83b4aa99955ea550d01f125baf33ede838dfd25ab8ec93ca62aef36ed988dbd577
Sha512 2c9f7dfbddbb807cf0183b45f17ee5747a8cb3e889512b67b0d6cceaf8fa54c438013229e80daa8fb46f904bf6e93a91f5f50f4b59bac4a291bc58f6fc8d1f75
SSDeep 12288:t1soooooigooonkiHXB8CZUqrOWaNlBvvt0RCYZJ5c/arhL+QK8Xj8a5DuY4HrHE:Lsoooooigooonb3B8dKOWgtt0RCYfm/I
TLSH 91F4F1643A25EC07E8F6A6F10CD4D67843BC1D8E7465D3CA1EE66CCB3EDAB06460119B
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hastane_Projesi.FrmBilgiDuzenle.resources
$this.Icon
[NBF]root.IconData
Hastane_Projesi.FrmDuyurular.resources
Hastane_Projesi.FrmGirisler.resources
Hastane_Projesi.FrmSekreterDetay.resources
Nerde
[NBF]root.Data
Hastane_Projesi.Properties.Resources.resources
tlyF
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\UoqmAlRNYW\src\obj\Debug\FHRQ.pdb
Module Name
FHRQ.exe
Full Name
FHRQ.exe
EntryPoint
System.Void Hastane_Projesi.Program::Main()
Scope Name
FHRQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FHRQ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
464
Main Method
System.Void Hastane_Projesi.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Hastane_Projesi.FrmGirisler::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hastane_Projesi.FrmBilgiDuzenle.resources
$this.Icon
[NBF]root.IconData
Hastane_Projesi.FrmDuyurular.resources
Hastane_Projesi.FrmGirisler.resources
Hastane_Projesi.FrmSekreterDetay.resources
Nerde
[NBF]root.Data
Hastane_Projesi.Properties.Resources.resources
tlyF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙