Suspect
PE Executable
MD5: 702503357d409579fe658b1a518d93a2
Size: 12.58 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 702503357d409579fe658b1a518d93a2 |
| Sha1 | 3d4a32be0683889cb04ac6b4bcd979da84f34115 |
| Sha256 | bbdb4e10ba2e085d83eeb97b10efc6f446cf040cfd10deb0ee48c375f4805953 |
| Sha384 | 27d47eebdaadb0401026a14db550dc0308bbf2bbc5ce0a1dab30588dd2b20b2f305d6f7929ddfa38bd77a1052fe9e881 |
| Sha512 | 4442faf1e7a7464f339233a78cda8e974f4c5d5c786f6724f28fc2d2fb005a1233f4c610cc5c88ce6566395759299a17588a09b1931d906276d8c68197b2cf47 |
| SSDeep | 196608:c1EfefPkBKaLNkbgMi4QWKaLNkbgRKaLNkbgBKaLNkbgv:c+WgMiH4Wg1WglWgv |
| TLSH | 64C61211B3E585B5E0BF0A38D87A86562A34BC049716C6BF57A4BD292D32FC09E31377 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12VC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 2secondary ignored: 10
bin
9img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>pe:dll
Shape
pe:exe>pe:dll>pe:dll
3 nodes
Path
pe:exe>pe:rsrc>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0xBFE200 size 5688 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |