Suspect
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
PeID
Microsoft Visual C++ v6.0 DLLNullsoft PiMP Stub -> SFX
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
| Info | Authenticode present at 0x19A62A size 10160 bytes |
| Info | Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_e74ba5e7.exe |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential