Suspicious
Suspect

01dc40c8eed7ca14008da6adfb4eb476

PE Executable
MD5: 01dc40c8eed7ca14008da6adfb4eb476
Size: 188.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 01dc40c8eed7ca14008da6adfb4eb476
Sha1 6db3344864e00e7cbd27fa212a89b7db0e23d0f2
Sha256 ad7ae1df63dc9f6ee4eabbeb4e9c0f98b2a1b1d69ad8bde9b564e998678310c4
Sha384 922bbaef549d039249f9f885f1a107b6d85576ba966d49eddc6300fae06a75c66ecf5a18ecd59a6648192d7204771396
Sha512 6b79efd89b22b3468a17cfd086c0a301980c72de9af8e7dcc2f23659cf84288f65bccee0ae1e4169a1b746f2e49f5d220bb16351066e22ab2c53e248e5d63449
SSDeep 3072:I3L+vYKVnpM9aBy37ItsUn0h05ilgCQzeioerIAy57dvCNVL1eCnQAM:npMMaMtF05pgvr87piek6
TLSH 4704491076E48931E6FB1A36B876992A497F79220FE4E2DF1750166E1E316C0CE34B37
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_a3010b4c.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2B800 size 10304 bytes
Info
PDB Path: D:\dbs\el\ddvsm\out\binaries\x86ret\bin\i386\Microsoft.VisualStudio.QualityTools.VideoRecorderEngine.pdb
[Authenticode]_a3010b4c.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙