Suspicious
Suspect

3419b20163a149fccc058ade17be1897

PE Executable
MD5: 3419b20163a149fccc058ade17be1897
Size: 312.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3419b20163a149fccc058ade17be1897
Sha1 c64c7e915e5d34fbc7afb812cb79bb70d2ccac2f
Sha256 3597ff9e459d5c2a239384d919595cbbd4587d10f70a595bbec9182891a665fe
Sha384 c829e60e44aa302dcb9bd34bca3ded174e2e42ae037d52ad7a9f7d0aefe3fb2868c161a0f6e0c0734a8c2f49103395a8
Sha512 280656aed5ad19f95594f3fd59620cce3b0890923ef97ee06d40a44568343d4ad3f3b80fddebf575cc2d5122aa8dae446e70ff29724af0e03bd4c807c835c31d
SSDeep 6144:imlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9zK:h1iw7gryNkSV1hy1Z1u2JLu9O
TLSH 4B647D11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_8177bdbe.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11504 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_8177bdbe.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙