Suspect
PE Executable
MD5: 583614371adddbcaf7f6c087479c77ab
Size: 5.79 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 583614371adddbcaf7f6c087479c77ab |
| Sha1 | 395cb23969206c1a5fabe746a0a891835d4c87e6 |
| Sha256 | 8ab5ad6e0c8b4cc906d162eb529b417b0d10a140bf295fb963cb63e70173c795 |
| Sha384 | b68ebd9ac00686a88239a0d28d0871e91d5ddf75a195e2862188e8ea49bf7c5ad36999eeef44763ad8d4f8617f76f7e0 |
| Sha512 | 12ca0cc5e9d13b1a2b66eb5d34b7df0cfa085290bada43d7520d25b9e9d8ba08874d637fab9a6637f04536f0c70ad206271e376f123dd52e9021b822ea01bc05 |
| SSDeep | 98304:HzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl3O:HhfefPtHxcp9ym3nltDUJV1O |
| TLSH | C946E101B3D695B6D1BF0638D87A56696734BC049316CBBF5394BD392E32BC04E323A6 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12VC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 18
STICH kept: 1secondary ignored: 17
bin
16img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>pe:dll>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll>pe:dll
4 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x54A600 size 242200 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |