Suspicious
Suspect

02d27db061b8d7a714fc541be13fd160

PE Executable
MD5: 02d27db061b8d7a714fc541be13fd160
Size: 2.94 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 02d27db061b8d7a714fc541be13fd160
Sha1 c9edd32302ee135adaf7c84a29c9827c76490381
Sha256 1da8f4e1ce5896277bfee5b9f6628f29a7534ae830108387b6aabeb4204c7039
Sha384 80cf477389b38e68d37fd15427645e1b0d273f89caaab6930332f30f59430787386a17172f6f42504bd3c240621a5059
Sha512 2cf5367e4bdbfa240df55cbe14693f707629670d89686371045aef1f1c32dcf9c6d0b5c0b085425a0494d4bf3c3f551dc1fe9f8422be7e40a2be77f23dced746
SSDeep 49152:XTUYO8JoB8BdWYwBrVwASOwGtlqq23l6K0BY2LIU6iTofR8lLqbGXPzI:XT/WT3/KR+UfR05XPzI
TLSH 87D59C16B25500FEE456C1B8964A5132F6717C8A6B717EEF02A4F6392E77AF02F38704
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
[Authenticode]_f5a012c2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gxfg
.tls
_RDATA
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2052
ID:0002
ID:2052
ID:0003
ID:2052
ID:0004
ID:2052
ID:0005
ID:2052
ID:0006
ID:2052
ID:0007
ID:2052
ID:2052-preview.png
RT_GROUP_CURSOR4
ID:0000
ID:2052
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2CB000 size 13256 bytes
Info
PDB Path: E:\x\x_rel_t6\out\build\RelWithDebInfo\Weixin.exe.pdb
[Authenticode]_f5a012c2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gxfg
.tls
_RDATA
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2052
ID:0002
ID:2052
ID:0003
ID:2052
ID:0004
ID:2052
ID:0005
ID:2052
ID:0006
ID:2052
ID:0007
ID:2052
ID:2052-preview.png
RT_GROUP_CURSOR4
ID:0000
ID:2052
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙