Suspicious
Suspect

20768341ce4da1908a03372e77b01e41

PE Executable
MD5: 20768341ce4da1908a03372e77b01e41
Size: 312.53 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 20768341ce4da1908a03372e77b01e41
Sha1 db39680858c673f1aba487255eaa6872983cddf5
Sha256 60f460751db886977f80fc65f858e48e78b6739b070a4ee57a35c3d9ac8b9e6c
Sha384 6d79ceca80435781a40805285db9dc94d13442e04699285d9bc1012f77275c64af2911ebbb73405de358cdd684737ac5
Sha512 f4f92a0e1439fefb6d1090ae0ea8bc358e2e3b507fa5afa8064ae747115e0564a41ead387452ef5c6d1c1380362fad153f03fefccfe198b87272343d02834689
SSDeep 6144:CmlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9:B1iw7gryNkSV1hy1Z1u2JLu9
TLSH 28647C11B9C48432C673383107B8E2B28DBDB8301D655B8F57A81D7A9F745D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_e9056381.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11472 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_e9056381.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙