Suspicious
Suspect

ScreenConnect.Windows.dll

PE Executable
MD5: 94216eb90ca53fbb175f0ee6adbfb663
Size: 1.73 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 94216eb90ca53fbb175f0ee6adbfb663
Sha1 48038f060a5042ff44a2d9a9be46368ecc8436fd
Sha256 da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522
Sha384 2d874f46321751883e7ccfe68355d5bc151b04bbad6cb3fc8659dc94583cd97c4aae63cf30fe8af295dc19a64a6348bd
Sha512 c6c7e2a63eaccc5703acf4cb482a9e441fb6e670a9086d3ade558a597b1fd6c17f5e5b7027d835b80ebf2c071f9442bde466f313ddb8456fe0d3e4db6d53b041
SSDeep 24576:VDhFj+Ifz3zvnXj/zXzvAAkGz8mvgtX79S+2bfh+RfmT01krTFiH4SqfKPTsUTHs:VDhJkGYYpT0+TFiH7efP
TLSH 4B85BD41E2D364F5D46B047888BF571ABA743C040325CAFB97D4AE3A6D33BC09A36796
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.gxfg
.gehcont
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1036
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll>pe:dll
Shape pe:dll>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\builds\cc\cwcontrol\Product\Windows\obj\Release\net20\ScreenConnect.Windows.pdb
Module Name
ScreenConnect.Windows.dll
Full Name
ScreenConnect.Windows.dll
Scope Name
ScreenConnect.Windows.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ScreenConnect.Windows
Assembly Version
25.2.4.9229
Assembly Culture
<null>
Has PublicKey
True
PublicKey Token
4b14c015c87c1ad8
Target Framework
<null>
Total Strings
145
Main Method
Not found or no body
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.gxfg
.gehcont
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1036
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙