Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
[Authenticode]_f7e6dc30.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x51000 size 10176 bytes
Info
PDB Path: D:\dbs\sh\el1q\0701_195252\cmd\u\obj\x64retail\sql\xml\xmlrw\dll\xmlrw.vcxproj\xmlrw.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙