Suspicious
Suspect

20144aadc5ecd13c0658feca465d6cec

Share on LinkedIn
Print
PE Executable
MD5: 20144aadc5ecd13c0658feca465d6cec
Size: 3.53 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 20144aadc5ecd13c0658feca465d6cec
Sha1 a2d13717556393eb0605e15906c950a4eac35de7
Sha256 3c6ee1def9b061e4591fd063ab29ea0df40e205a9c7540e23716f32313568f32
Sha384 02d87fb2188a80fabc025100439cf207b72b25b2abaa6dbd63eb233fac6031d42804d987da9c8d007d5ee220483b4bbd
Sha512 986e5e1b0d29d32dd9c4698d3c6ed6d5bf95925970a4334a614f39006c6ab44c6bf20999e581c41aeb5ed7cd97b43ef52d8eae20719d5d8719575e6309a5bc67
SSDeep 49152:lMr6FQ0RIVvlifZ4NfamIzMShTmhTHjxpPL33pJW9xgVuw3wyfZ78bn9A35TL:9RYYT8HVB3pmGw63hL
TLSH 77F58CD2A7A600E8E877F23CC5568117E7F2B81717709BCB15A44A760F23AD12E3E716
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Overlay_693058df.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
AFX_DIALOG_LAYOUT
ID:0067
ID:1033
RT_BITMAP
ID:006C
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0071
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_693058df.bin (497 bytes)
Info
PDB Path: C:\rb5\hostagent-src\Release\RBHostSvc6400.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙