Suspicious
Suspect

bd6cc6112cccca6dc0b0127786703eb9

PE Executable
MD5: bd6cc6112cccca6dc0b0127786703eb9
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bd6cc6112cccca6dc0b0127786703eb9
Sha1 21d9a73f135fe2beebb1f254061d7bcbdd82668c
Sha256 a8f291510e59a0d9929809d9d7de3cc1958df12e14634895a513f95e3e37b7cb
Sha384 2901c5691f90a86ec3f19b5cef2f0ef574ab7b096d4b7607597eec138cc97f14aec46244919be5036f6aa0655fca41c0
Sha512 47fe6365447c3b6f268868a2d04a72365751eb3c253637ac18d71e6251492df2a0630416f375b9e58c1b45692b140fd4f867bd42d920bc977e5f11c38e40e582
SSDeep 24576:mMmuaaHiawo2x4r1AgdcV6TIzR6POqQnxRxUORR:mMmuaauo2MA+uld6P+W8
TLSH 324512942309DE02D9639BF45930D7B81BB86ED5B820D3179EEA7DEBB83671428443D3
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
IIvg
[NBF]root.Data
[NBF]root.Data-preview.png
Kare
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ftqf.exe
Full Name
Ftqf.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
Ftqf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ftqf
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Ftqf.exe
Full Name
Ftqf.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
Ftqf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ftqf
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
290
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
IIvg
[NBF]root.Data
[NBF]root.Data-preview.png
Kare
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙