Suspicious
Suspect

1cffb2bbc8c72d67342461356e4a0cfd

PE Executable
MD5: 1cffb2bbc8c72d67342461356e4a0cfd
Size: 312.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1cffb2bbc8c72d67342461356e4a0cfd
Sha1 093b78fcf7ea134a0ac8b8a0d2769108d062af82
Sha256 206eeba1fcf7b2100ebe21dba990579a4b04b5b2b2a3a4467f118e6f6023f168
Sha384 3b58810404977f95250c73dc4e05981c021b23cb4ad62b2e6e16482834c3d496b35595082699032bb8fa850f67c6ceeb
Sha512 03c6e3d278a46a6f0f7d12fab51fe0aa2b69a591e36ef4baee131b3c9cce58ac8aa5008a702dd1a23d64643ca56833c01e6a4754480f58716bcb3217cf4985e6
SSDeep 6144:imlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji94:h1iw7gryNkSV1hy1Z1u2JLu94
TLSH D2646C11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_af96e4e0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11504 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_af96e4e0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙