Suspicious
Suspect

PE Executable
MD5: db0da77a5aa927ba6b36c02e953488be
Size: 621.57 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 db0da77a5aa927ba6b36c02e953488be
Sha1 eb6063b00f8433038e3aad4dac7dff7c609c1e33
Sha256 869bf087a9bf33800b03f3b2ee202abc55fdb152fdee40a3d3096e28803669f6
Sha384 bc0a737b80b0bad957141a1478baee176f030363db2413cd4c1d6ff85f6646bb6ccaecc8e8528d6b86ec1bd172307121
Sha512 ce5774b334b9e3f6445b222d626f7337c49e03a872c0f7cc4a7582526753e3deb0321c4fb84e5910bf3cab1e33c6e22e845fabf799fa7af28f1dc3cf29933895
SSDeep 12288:7SfRerx/ux/GV7vdVotdMx/Qzyp9XNuVhMoewfl7U/DmDWfGy+ZgC+R5VaadlMYP:7lxWxeVzdyMxIze98hMoes+pGyogCga6
TLSH DFD4E05476A49807CA7E96F10D22F6700BF92DEE6911D3CA8DC96EDF38E9F085D00A53
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pansiyon_kayıt1.FrmAdminGiris.resources
$this.Icon
[NBF]root.IconData
Pansiyon_kayıt1.FrmAnaForm.resources
evet
[NBF]root.Data
timer1.TrayLocation
Pansiyon_kayıt1.FrmGazeteler.resources
Pansiyon_kayıt1.FrmMüzik.resources
axWindowsMediaPlayer1.OcxState
Pansiyon_kayıt1.Properties.Resources.resources
syOXZr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\CVFPHcIntE\src\obj\Debug\JAucAV.pdb
Module Name
JAucAV.exe
Full Name
JAucAV.exe
EntryPoint
System.Void Pansiyon_kayıt1.Program::Main()
Scope Name
JAucAV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JAucAV
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
678
Main Method
System.Void Pansiyon_kayıt1.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Pansiyon_kayıt1.FrmAnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
JAucAV.exe
Full Name
JAucAV.exe
EntryPoint
System.Void Pansiyon_kayıt1.Program::Main()
Scope Name
JAucAV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JAucAV
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
678
Main Method
System.Void Pansiyon_kayıt1.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Pansiyon_kayıt1.FrmAnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pansiyon_kayıt1.FrmAdminGiris.resources
$this.Icon
[NBF]root.IconData
Pansiyon_kayıt1.FrmAnaForm.resources
evet
[NBF]root.Data
timer1.TrayLocation
Pansiyon_kayıt1.FrmGazeteler.resources
Pansiyon_kayıt1.FrmMüzik.resources
axWindowsMediaPlayer1.OcxState
Pansiyon_kayıt1.Properties.Resources.resources
syOXZr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙