Suspicious
Suspect

58082a5543e9a04a66a49097c4da851b

PE Executable
MD5: 58082a5543e9a04a66a49097c4da851b
Size: 1.67 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 58082a5543e9a04a66a49097c4da851b
Sha1 41ad155598fd9acb0d8c4b72ce9056b48ef9c3de
Sha256 a83a0ea185e95684a202963b7f4acb40e4e148d670ef149aff96853dc46e16c1
Sha384 eb4dd23bb58a08647b229338f556082f5f302afda0b2fa76f2a5c4dcbe87ddd275d5e9fc13d3b1fd3f15b2009eea8097
Sha512 5328989198bddedcd8d7f70cc0b64937f18e94c28da3320358f28f6cd66ab6339278a995620c1c3cdf94dfcb7160af8819aecff0bdb5440a32f01795f976c3a5
SSDeep 49152:ADeIVGK1N58ed04Zk6U5PZ4cuLXbl5HmLyAtlQVU92V:aeIVhyy6Z4LLZxmWYlQVUm
TLSH CA7523642315DE01C9624BF49D31EBB81BF56E90AA21D3178DFA7DE7B83A7086C052C7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
DHDa
[NBF]root.Data
[NBF]root.Data-preview.png
Kare
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
LJov.exe
Full Name
LJov.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
LJov.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LJov
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
LJov.exe
Full Name
LJov.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
LJov.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LJov
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
DHDa
[NBF]root.Data
[NBF]root.Data-preview.png
Kare
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙