Suspicious
Suspect

59a2ba1e142177f44e4a23c5f9aa4b02

PE Executable
MD5: 59a2ba1e142177f44e4a23c5f9aa4b02
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 59a2ba1e142177f44e4a23c5f9aa4b02
Sha1 59064ae941fa204723a58ee635723575437d6b5d
Sha256 23ec48eb6bd59bbfd84c8d05e14862d7bdf736af090de81ddd6dc29b7a0e7ef0
Sha384 d3c42c4d0af0de5b517ae29780e873e750bfbdb513003f8a42d5d8684ad3bb8b20967ff9b04d8987d560c51a44a57179
Sha512 15ee25c9a23c02fed45bb797d8e6678cdaa2f431f1bfad81d86bb36a3ec59fb66e224c13e05897185ee4d1d1f58b3db50f4ea79abff97ddccb378a3fb9732de4
SSDeep 24576:m4RZa0VzMJVIyap6582v4/MMnOrhUa/AnfwGaSAL8zUlF:m4Da0VCxapR2A3exAIGo8zUlF
TLSH 5A3501541319CE02C8A24BF49D71E3F91BB96ED4A910D3678EEA7DEB797A71028143C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
gnfu
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
EbUU.exe
Full Name
EbUU.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
EbUU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EbUU
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
EbUU.exe
Full Name
EbUU.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
EbUU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EbUU
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
gnfu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙