Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
[Authenticode]_a08bf704.p7b
Overlay_ffbabe2c.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:16393
ID:16393-preview.png
ID:0002
ID:16393
ID:0003
ID:16393
ID:0004
ID:16393
ID:0005
ID:16393
ID:0006
ID:16393
RT_GROUP_CURSOR4
ID:0065
ID:16393
RT_VERSION
ID:0001
ID:16393
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
Info
Overlay extracted: Overlay_95303373.bin (189951 bytes)
Info
Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_8dc76a98.exe
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙