Suspicious
Suspect

c7ed106493f459e9aebe37be31f84d8e

PE Executable
MD5: c7ed106493f459e9aebe37be31f84d8e
Size: 1.21 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c7ed106493f459e9aebe37be31f84d8e
Sha1 4feaad3d3556b70049ebae14e5306c4c304586eb
Sha256 b59fe70e499dfd4f13fd545ec1892a10dd8a913ebc41190d69ecca2f4135c02f
Sha384 d349d5aacfe097c5f3e6b69c384dcf62e1d36afd6ebe5ed38194fe4205f7154970b2a8af02ab7adc3233d02ede010788
Sha512 97fdc97afca876e3509d76a968a92550ee8899af13a702b16a71deb41d64eb6105805d09b4d1b897382e33a8ad7272377562e5ed7d138e7125010ab766575b13
SSDeep 24576:pkq+DRgw0Rn+8TxpfYafQ/MpV3rIf2cimm:eD6w0d+QbTTpV3rIf2cib
TLSH 3F45E19C3200F98FC807CE768D64EEB4AA606CA68707D20395E71DEBBD1D5979E051E3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
WiOW
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
scYF.exe
Full Name
scYF.exe
EntryPoint
System.Void WaterTower.Program::Main()
Scope Name
scYF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
scYF
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void WaterTower.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void WaterTower.Program::‫‌‫‪‮‬‍‪‌​‭‫‮‫‭‏​‍‏‬‬‪‍​‏‮()
ldc.i4 -2041759630
ldc.i4 -184110303
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_003F: newobj System.Void WaterTower.FormTurm::.ctor()
nop <null>
ldc.i4.0 <null>
call System.Void WaterTower.Program::​‫‏‌‌‎​‪‬‪‪‪‭‪‍‏‬‌‮‏‎​‏‮(System.Boolean)
nop <null>
ldloc.0 <null>
ldc.i4 -1916623451
mul <null>
ldc.i4 -1012152764
xor <null>
br.s IL_000B: ldc.i4 -184110303
newobj System.Void WaterTower.FormTurm::.ctor()
call System.Void WaterTower.Program::​‭‭‭‎‌‬‏‎‭‏‏‏‌‍‏‭‭​‏‎‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterTower.Properties.Resources.resources
Kare
[NBF]root.Data
WiOW
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙