Suspicious
Suspect

425a05835b91500f3bec23b9a0149a87

PE Executable
MD5: 425a05835b91500f3bec23b9a0149a87
Size: 197.92 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 425a05835b91500f3bec23b9a0149a87
Sha1 80af59ba4e45ea94191a5653c3680058c7c3c782
Sha256 728d7797fe0763c652d97bc831752a03d6d21ea0d625aab80a428e63e0743b4b
Sha384 1e377167d9baceafd3cc0674286ed91af4a39023a0cc6288ad085a8d71bfacb2d88ea86115e1b6187eae58f864967e64
Sha512 dc4c78d5c2834c6c8483800a7b0996fe633e75d7f344c7b708d7b291a4c9dbc30df30429896b1d93004b9562be06cfdc1c55f8d476b8a7085b662894327b0561
SSDeep 3072:myAB89t7YWHQQQrGOEVNB1nFp3v7DFcrKapQ3mptf2Ix+f1r8:mrwsQgGPNLnvv7DFc2apQYtf2u+fi
TLSH 62146BC5B2A40585D9B7C3B8CAA74D97A933B4412370C7DF0A6086797F63BE8B13A741
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
[Authenticode]_1cc7ab02.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
.idata
Resources
RT_MESSAGETABLE
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2E400 size 8480 bytes
Info
PDB Path: winfsp-x64.dll.pdb
[Authenticode]_1cc7ab02.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
.idata
Resources
RT_MESSAGETABLE
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙