Suspicious
Suspect

PE Executable
MD5: 3ecc140ff8e73d835426dcb5a6cbced3
Size: 312.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3ecc140ff8e73d835426dcb5a6cbced3
Sha1 8897ffbfde4bf56479e0448c3b593bb3f10f857a
Sha256 1d688781a79012c8db3c948d86b9a9b26dde6b1e6bc70ee3f21e681be8a8711a
Sha384 36d1c4930f79fff151b8e9e21ce91b60cc45a9e1d5b03cbdb5aa5f99194f5d378094d5eb89f132eca103950cc9d6ae65
Sha512 c7b9982d63050d2de3a9f4fa3386662191274b05cc7a6849225d2d699a6c88395c7d8ce9b2631e5c1e96ad72e04f595fe70fa78b9abad93dcce0d533f69f8a72
SSDeep 6144:dmlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFti99V:Y1iw7gryNkSV1hy1Z1u2JLI97
TLSH 1F646D11B9C48432C673383107B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_578d9262.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11480 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_578d9262.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙