Suspicious
Suspect

b310630206af709a40f216c199caa651

PE Executable
|
MD5: b310630206af709a40f216c199caa651
|
Size: 814.08 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
b310630206af709a40f216c199caa651
Sha1
80764827db0c1b8e95c458c1e7c9d509f22c2221
Sha256
362f141bda759af6502f936adf999c6cf54fdc8d1951e103936ece788c3e0139
Sha384
09224199fb21a97e6efeddf4042911534680610892e7bd14a355895173635bf64c91c256e82a27fcb7af9f5c7f93551c
Sha512
b485641db41c2895e5f6aa773f8bf9ba330b27bd40cca42571bc4e8ab9b770d469be9e594e4136537fb7fb22484c7a87574294dd6d470a91b345699806e39e6e
SSDeep
12288:XrNbUyAHQB2LZMUbgWTjqtNbF42vwpQeDfuGZJSlXlk7y2C8wZ7U:bNg1HDNJcZ42vw7fW++dP
TLSH
8A05E030365BD605D8660BB00C34D3F513B97EADBA14C74E6EE92E9FFD262135B112A2
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StokTakip.BrandsManage.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Font
$this.Margin
btnCreateBrand.Location
btnCreateBrand.Size
btnDeleteBrand.Location
btnDeleteBrand.Size
groupBox1.Location
groupBox1.Size
lst_Brands.Dock
lst_Brands.Location
lst_Brands.Size
txtBrandName.Location
txtBrandName.Size
StokTakip.Form1.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Icon
[NBF]root.IconData
$this.Margin
$this.StartPosition
CTT
[NBF]root.Data
dilToolStripMenuItem.Font
dilToolStripMenuItem.Size
englishToolStripMenuItem.Size
markalarToolStripMenuItem.Size
menuStrip1.Size
menuStrip1.TrayLocation
satışToolStripMenuItem.Font
satışToolStripMenuItem.Size
tanımlarToolStripMenuItem.Size
StokTakip.PhoneCaseCreate.resources
$this.ClientSize
btn_AddStock.Location
btn_AddStock.Size
btn_Clear.ImeMode
btn_Clear.Location
btn_Clear.Size
btn_save.Location
btn_save.Size
cb_cases.Location
cb_cases.Size
cb_color.Location
label1.Location
label1.Size
label2.Location
label2.Size
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label7.Location
label7.Size
label7.TextAlign
lbl_info.Font
lbl_info.Location
lbl_info.Size
nm_price.Location
nm_price.Size
nm_qty.Location
nm_qtyAdd.Location
tabControl1.Location
tabControl1.Size
tabPage1.Location
tabPage1.Padding
tabPage1.Size
tb_name.Location
StokTakip.PhoneCaseManage.resources
StokTakip.PhoneCreate.resources
$this.ClientSize
btn_Clear.Location
btn_save.Location
btn_save.Size
cb_brand.Location
label1.Location
label1.Size
label2.Location
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label6.Location
nm_price.Location
tb_IMEI1.Location
tb_IMEI2.Location
tb_modelCode.Location
tb_name.Location
StokTakip.PhonesManage.resources
$this.ClientSize
btn_deletePhone.Location
btn_deletePhone.Size
btn_newPhone.Location
btn_newPhone.Size
filter_btn_search.Location
filter_btn_search.Size
filter_cb_brand.Size
filter_tb_modelcode.Location
filter_tb_modelcode.Size
grid_phones.Location
grid_phones.Size
StokTakip.Properties.Resources.resources
HwUx
[NBF]root.Data
[NBF]root.Data-preview.png
definitions
iconfinder_search_322497
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: C:\Users\Administrator\Desktop\Client\Temp\nBdLcxUJlE\src\obj\Debug\eSif.pdb

Module Name

eSif.exe

Full Name

eSif.exe

EntryPoint

System.Void StokTakip.Program::Main()

Scope Name

eSif.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

eSif

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

255

Main Method

System.Void StokTakip.Program::Main()

Main IL Instruction Count

12

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> call System.Void StokTakip.Ayar::GetLatestLanguage() nop <null> newobj System.Void StokTakip.Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

b310630206af709a40f216c199caa651 (814.08 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StokTakip.BrandsManage.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Font
$this.Margin
btnCreateBrand.Location
btnCreateBrand.Size
btnDeleteBrand.Location
btnDeleteBrand.Size
groupBox1.Location
groupBox1.Size
lst_Brands.Dock
lst_Brands.Location
lst_Brands.Size
txtBrandName.Location
txtBrandName.Size
StokTakip.Form1.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Icon
[NBF]root.IconData
$this.Margin
$this.StartPosition
CTT
[NBF]root.Data
dilToolStripMenuItem.Font
dilToolStripMenuItem.Size
englishToolStripMenuItem.Size
markalarToolStripMenuItem.Size
menuStrip1.Size
menuStrip1.TrayLocation
satışToolStripMenuItem.Font
satışToolStripMenuItem.Size
tanımlarToolStripMenuItem.Size
StokTakip.PhoneCaseCreate.resources
$this.ClientSize
btn_AddStock.Location
btn_AddStock.Size
btn_Clear.ImeMode
btn_Clear.Location
btn_Clear.Size
btn_save.Location
btn_save.Size
cb_cases.Location
cb_cases.Size
cb_color.Location
label1.Location
label1.Size
label2.Location
label2.Size
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label7.Location
label7.Size
label7.TextAlign
lbl_info.Font
lbl_info.Location
lbl_info.Size
nm_price.Location
nm_price.Size
nm_qty.Location
nm_qtyAdd.Location
tabControl1.Location
tabControl1.Size
tabPage1.Location
tabPage1.Padding
tabPage1.Size
tb_name.Location
StokTakip.PhoneCaseManage.resources
StokTakip.PhoneCreate.resources
$this.ClientSize
btn_Clear.Location
btn_save.Location
btn_save.Size
cb_brand.Location
label1.Location
label1.Size
label2.Location
label3.Location
label3.Size
label4.Location
label4.Size
label5.Location
label5.Size
label6.Location
nm_price.Location
tb_IMEI1.Location
tb_IMEI2.Location
tb_modelCode.Location
tb_name.Location
StokTakip.PhonesManage.resources
$this.ClientSize
btn_deletePhone.Location
btn_deletePhone.Size
btn_newPhone.Location
btn_newPhone.Size
filter_btn_search.Location
filter_btn_search.Size
filter_cb_brand.Size
filter_tb_modelcode.Location
filter_tb_modelcode.Size
grid_phones.Location
grid_phones.Size
StokTakip.Properties.Resources.resources
HwUx
[NBF]root.Data
[NBF]root.Data-preview.png
definitions
iconfinder_search_322497
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙