Suspicious
Suspect

PE Executable
MD5: 294ab44f0f43b4a1f04276fd6bacb39d
Size: 312.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 294ab44f0f43b4a1f04276fd6bacb39d
Sha1 97e2ed01f00199f3047b26ebd0ca5a5f41ebc4e6
Sha256 2bad623d0ec0d17a3844d3a6d443a5c221e5924a76485f2070bbedff85220ba2
Sha384 125a095a0f9020683c9da19a5661f971ae7ebba345d736bcc98db11d046acfbd9ea3fff1738b6cbfb23e429f057e308a
Sha512 bdc7d4ee10c7ddb6a57cf42ff7661fb3b249e84f175fbe1cafd218a2f4869b4c7db47e91ba29fcc0bfb22994cd0d662c4dbc5009d017110c4947fe55e28b4424
SSDeep 6144:imlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9Q:h1iw7gryNkSV1hy1Z1u2JLu9Q
TLSH 97646C11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_742ee537.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11504 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_742ee537.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙