Suspicious
Suspect

d9d44e60625da4e235f3ae116e3e1bd8

PE Executable
MD5: d9d44e60625da4e235f3ae116e3e1bd8
Size: 1.23 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 d9d44e60625da4e235f3ae116e3e1bd8
Sha1 fcef892ac5d9cafa830b60f7b77a56399bfb3687
Sha256 fc0fd66e13fb8cbfe445c6b356bd1ada335907577cb495a0d0fa5e40400d7c28
Sha384 84cc28db246315f96028c356814266c48e65f191ceecb74275d13ecf9c297189a5a781aff06dc874bfabc54caa288cf9
Sha512 5f820cd40cee3d2ebd32de7ed7fb2e94ddc58e2ae1f74dcf6a92c04445ce6c9068792d05da1c008f1bed5d91a70f1e27e56db5007b0beee0a01c39d4c429ab58
SSDeep 24576:odDJr4C9g0rTbuufUE2k1cpj8sPaPWN8rzzCZ:odDj9yWUEKtpKrz
TLSH 7D4522981A94DA06C8486FB44E30F1752A781FDDA912C617AFDEBCEFF87F6156C04086
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Properties.Resources.resources
AI
[NBF]root.Data
YWrc
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
EvQe.exe
Full Name
EvQe.exe
EntryPoint
System.Void LabirentUygulamasi.Program::Main()
Scope Name
EvQe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EvQe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
119
Main Method
System.Void LabirentUygulamasi.Program::Main()
Main IL Instruction Count
22
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldsfld System.UnhandledExceptionEventHandler LabirentUygulamasi.Program/<>c::<>9__0_0
dup <null>
brtrue.s IL_0032: callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
pop <null>
ldsfld LabirentUygulamasi.Program/<>c LabirentUygulamasi.Program/<>c::<>9
ldftn System.Void LabirentUygulamasi.Program/<>c::<Main>b__0_0(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.UnhandledExceptionEventHandler LabirentUygulamasi.Program/<>c::<>9__0_0
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void LabirentUygulamasi.AnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Properties.Resources.resources
AI
[NBF]root.Data
YWrc
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙