Suspicious
Suspect

16e5a492c9c6ae34c59683be9c51fa31

PE Executable
MD5: 16e5a492c9c6ae34c59683be9c51fa31
Size: 139.26 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 16e5a492c9c6ae34c59683be9c51fa31
Sha1 97031b41f5c56f371c28ae0d62a2df7d585adaba
Sha256 35c8d022e1d917f1aabdceae98097ccc072161b302f84c768ca63e4b32ac2b66
Sha384 0c9677ab57a4ae5b912fe92a2f11318ba0de7d7673bb7cd47ba6e561ad627557d02eb8a6df22c3e3dfe16aefe9672d94
Sha512 20fd369172ef5e3e2fde388666b42e8fe5f0c2bfa338c0345f45e98af6561a249ba3ecc48c3f16efcc73f02ecb67b3ddb1e2e8f0e77d18fa00ac34e6379e50b6
SSDeep 3072:t0iX+jLyDcqaH9a6DFHo6MjD7VbZaZaZ8Xwlk4MHWZpt:t07yDSvdoRj2up
TLSH 51D35B0772A500BFE1668638C5630A09E777B8211770DBAF33A4429D9F277E19D3AF61
PeID
Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit )
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
.0Dev
Resources
RT_MANIFEST
ID:0002
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Malware\Desktop\hack tool\Backdoor\SheetRat\SheetRat\bin\Release\Stub\UserMode.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
.0Dev
Resources
RT_MANIFEST
ID:0002
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙