Suspicious
Suspect

e4d78bedb76416f6930e6a911a4f22d5

PE Executable
MD5: e4d78bedb76416f6930e6a911a4f22d5
Size: 873.47 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 e4d78bedb76416f6930e6a911a4f22d5
Sha1 4a0ffba1b24441d86b89364eb927bc845341498d
Sha256 bcd2512db9d2789cd0ad058f0c2fd676cf37368174a75a95306f229df5d66dd2
Sha384 7e9a14051730b11c0c266a1ca27e27d564289d783d9af2c6af59bbec63f7a0c719eccb07a8941c22b9457a98f08c9fee
Sha512 0b3faa3ba3d38ecd64a455eb95cc0b7df0ad8447dd2c9bea6e887581135cf825863cc469ff573ac675907d2937f3ee85e847069b533632a3ced197b95de06930
SSDeep 12288:9Wcruda2KfKPdIuVXKXRz5HFPo2TGgBQQO7q5szCLTwaN0mD1cZQjuyojGY:95ukfmKXRz5QqdICL8K0meZQ4jGY
TLSH F505D02172A5AF51C5B903F81520E77107F26CAFF53AD31A1CC66CEF3979B814A12A93
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EczaneOtomasyon.AnaMenu.resources
EczaneOtomasyon.Hakkinda.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.GenelMenu.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.Properties.Resources.resources
IZOO
[NBF]root.Data
[NBF]root.Data-preview.png
jj
[NBF]root.Data
EczaneOtomasyon.SaglikArsiv.resources
ımageList1.TrayLocation
Name Value
Module Name
wpaX.exe
Full Name
wpaX.exe
EntryPoint
System.Void EczaneOtomasyon.Program::Main()
Scope Name
wpaX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wpaX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1124
Main Method
System.Void EczaneOtomasyon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EczaneOtomasyon.GenelMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
wpaX.exe
Full Name
wpaX.exe
EntryPoint
System.Void EczaneOtomasyon.Program::Main()
Scope Name
wpaX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wpaX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1124
Main Method
System.Void EczaneOtomasyon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EczaneOtomasyon.GenelMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
wphuhuhuhu
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EczaneOtomasyon.AnaMenu.resources
EczaneOtomasyon.Hakkinda.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.GenelMenu.resources
ımageList1.ImageStream
[NBF]root.Data
EczaneOtomasyon.Properties.Resources.resources
IZOO
[NBF]root.Data
[NBF]root.Data-preview.png
jj
[NBF]root.Data
EczaneOtomasyon.SaglikArsiv.resources
ımageList1.TrayLocation
No malware configuration was found at this point.
PDB Path PATH
wphuhuhuhu
e4d78bedb76416f6930e6a911a4f22d5
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
e4d78bedb76416f6930e6a911a4f22d5
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
e4d78bedb76416f6930e6a911a4f22d5
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙