Suspicious
Suspect

9cd3101160696b4581ace3a75f0d928f

PE Executable
MD5: 9cd3101160696b4581ace3a75f0d928f
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9cd3101160696b4581ace3a75f0d928f
Sha1 a2ebb5ec5c320b6da4e9748cc91bf93e9219438a
Sha256 bb036570b24bde4cb134dfbcdced716d2f5ec1337e7139a8fe08da1b37c06a08
Sha384 3f7556ba3d6475f2d83591dfa3d5270498d7908de4dc8832b491413678e95475251de7c30d4272c07ae28c66f40fb678
Sha512 b4d08852476d93694016fc91fdd632d2fa4db16c97413c48a100b95bcf945ad7fd0bd25cafee673225c032ce10c6afe217e337bf2fae57e5f3564f07e582bc79
SSDeep 24576:mtRGRIaA+twTq/AJm4hTfRQe8SAEYu4ojjL3mRm+XwBx0//:mt6M+twTCAXNRQvSdV40L4vXL/
TLSH F13512942355DE06D8535BF55970E7F407F89EE4A910C3078EFABEEBB83AB4518182C2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
Zkxy
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
BeqF.exe
Full Name
BeqF.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
BeqF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BeqF
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
BeqF.exe
Full Name
BeqF.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
BeqF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BeqF
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
Zkxy
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙