Suspicious
Suspect

PE Executable
MD5: d5412cced06a388ebb04a6336a368e41
Size: 735.23 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d5412cced06a388ebb04a6336a368e41
Sha1 ae2bb657ed66a34e6078f858815d628fe75c5277
Sha256 32d7e75def5521ce78e913d29df7a2b2e5a73a0cf78d134c812b131a6bb961b7
Sha384 c825939c31fb4dd9676857f395c3dad81a6e480d4788c66353fd56b21c5ebc43b87db158d8534539d5bd8f581c9d7768
Sha512 311cd3f864a222a4417f4a0f093d330d370b43bd63204ecb89f1beeb0831a7c62f2f6ea7473ee216d05de74728073f7116ca76fa456bfb5942644b01775342d0
SSDeep 12288:33/PFx/ux/GV7vdVotdMx/Bdd4QdTdiuSfxnHXNoANOUtA/UMAI8t5E/RXotx/:3lxWxeVzdyMxBRPadoANOUqUMAIb/RXE
TLSH 2CF4F14876A08827CE789AF10C31F67407B81EEEB801D3D98DD9ADDB79DAF045A40E57
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pansiyon_kayıt1.FrmAdminGiris.resources
$this.Icon
[NBF]root.IconData
Pansiyon_kayıt1.FrmAnaForm.resources
evet
[NBF]root.Data
timer1.TrayLocation
Pansiyon_kayıt1.FrmGazeteler.resources
Pansiyon_kayıt1.FrmMüzik.resources
axWindowsMediaPlayer1.OcxState
Pansiyon_kayıt1.Properties.Resources.resources
qexT
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\NlcYAYynzh\src\obj\Debug\wNsB.pdb
Module Name
wNsB.exe
Full Name
wNsB.exe
EntryPoint
System.Void Pansiyon_kayıt1.Program::Main()
Scope Name
wNsB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wNsB
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
678
Main Method
System.Void Pansiyon_kayıt1.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Pansiyon_kayıt1.FrmAnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
wNsB.exe
Full Name
wNsB.exe
EntryPoint
System.Void Pansiyon_kayıt1.Program::Main()
Scope Name
wNsB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wNsB
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
678
Main Method
System.Void Pansiyon_kayıt1.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Pansiyon_kayıt1.FrmAnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pansiyon_kayıt1.FrmAdminGiris.resources
$this.Icon
[NBF]root.IconData
Pansiyon_kayıt1.FrmAnaForm.resources
evet
[NBF]root.Data
timer1.TrayLocation
Pansiyon_kayıt1.FrmGazeteler.resources
Pansiyon_kayıt1.FrmMüzik.resources
axWindowsMediaPlayer1.OcxState
Pansiyon_kayıt1.Properties.Resources.resources
qexT
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙