Suspicious
Suspect

5a74607697701830113d1ac3f61174e6

PE Executable
MD5: 5a74607697701830113d1ac3f61174e6
Size: 312.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5a74607697701830113d1ac3f61174e6
Sha1 df7e37a708271620b61648cfc2cf8404d6bddce3
Sha256 e874f27ec4e6b0dda043a3768300dc84d7205f47e6ad1e7bbc3ef7805a7573fd
Sha384 32bd3ec6f7e973f80c3a6bc5351383c1ad16e72756276346d7a569d6158d1dbe4456ddaa5065edce47c7367ddee1b2f6
Sha512 08daa267d4f01bf3ed3346357884900fdc9241ca736ed5f0a96f9606464d981aaa89dd092db167467710afddb5bf5a71c09496524ba9594c18bd001f3514a212
SSDeep 6144:ymlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9:R1iw7gryNkSV1hy1Z1u2JLu9
TLSH FB647C11B9C48432C673383147B8E2B28DBDB8301D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_08e21b66.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11488 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_08e21b66.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙