Suspect
7da1c529f1cde0f28f08d5e90a64f19c
PE Executable
MD5: 7da1c529f1cde0f28f08d5e90a64f19c
Size: 12.81 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 7da1c529f1cde0f28f08d5e90a64f19c |
| Sha1 | 802f55bbb5a7039babe432b2d784dcc699fa7a13 |
| Sha256 | fd2479e51259747153a3ce46264e0f3f3fac1d6eadcc0efb915ba5f35ccc5b18 |
| Sha384 | 38074bb7927a6f13eff6cf5c479d4a5a5a91e577f603a977f248877d372204344008e059fa8bd9fa46182f73a9a80fbc |
| Sha512 | 061f781f349e6fbace8762a2084d2a101989946f7f669f7aa1c696808eb7d95674d85dcc207f9c23b707d975539e18c647814cb24e90f1c387c8743704c78d1c |
| SSDeep | 393216:Yq5VDBCDxXQEZq5VDBCDxOq5VDBCDxdq5VDBCDxq:YpCEZp4pjpQ |
| TLSH | 08D61211B3D594B5D0BF0638D83A92656B35BC008B66C6AF6394B96D2D33BC08E32777 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikonVC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 2secondary ignored: 10
bin
9img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>pe:dll
Shape
pe:exe>pe:dll>pe:dll
3 nodes
Path
pe:exe>pe:rsrc>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0xC35600 size 5688 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |
No malware configuration was found at this point.
You must be signed in to view YARA rules.