Suspicious
Suspect

30cb9db600cbd4a03defb987066e3956

PE Executable
MD5: 30cb9db600cbd4a03defb987066e3956
Size: 312.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 30cb9db600cbd4a03defb987066e3956
Sha1 d7313f4cbbc1ea4dca4954f58052fd671c0e3dfa
Sha256 077bfdd22b49adeeb86e80050de6bbf2ca9616279c426e21847f476761cba27d
Sha384 4b16f03b2280e8ab8d78f391cdc8f43f6339c237bcb6bf1ad6915653b476844a149843ed9c58fc576301f9866c07d392
Sha512 cb27f5e254a6f2055b891c93f7a2c4fc7d2137a4a445dff85245319b48eab1bee06e0e848a15562937096a40c80f82a6810ff2caf61e3a09a7ecc2e2f44d3da9
SSDeep 6144:imlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji95:h1iw7gryNkSV1hy1Z1u2JLu95
TLSH C7646C11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_a5ae2179.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11504 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_a5ae2179.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙