Suspicious
Suspect

PE Executable
MD5: 9afde42cf03622ca680fad3c9ca851a0
Size: 5.64 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9afde42cf03622ca680fad3c9ca851a0
Sha1 5560b1409e51f5970dfd8f4fda0bfa60044d556d
Sha256 aa04dce309e673624bd6778de8ceb8c193b2412e48eb6b160b72fec00cbaacb4
Sha384 b76222659f530d48bfb2e5bd4497ca809bebbd6995d6da0ddb6bf05efb56ad6cc57b1bb0324fb8b89c3262851d60b2f5
Sha512 e5175213d1173af9298a600885710d9310aea1baffb0cd76e212f10f1e1413538e3f36d8d41f884b950a22686249168fdede1bfe05f773b66312d91db4e860ae
SSDeep 98304:CzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:ChfefPtHxcp9ym3nltDUJV
TLSH EF46E101B3D695B6D1BF1638D87A52696734BC049316CBBF5394BD392E32BC04E323A6
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12VC8 -> Microsoft Corporation
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
FILES
ID:0000
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
ScreenConnect.Client.dll
ScreenConnect.ClientService.dll
ScreenConnect.Core.dll
ScreenConnect.Windows.dll
ScreenConnect.WindowsAuthenticationPackage.dll
ScreenConnect.WindowsBackstageShell.exe
ScreenConnect.WindowsBackstageShell.exe.config
ScreenConnect.WindowsClient.exe
ScreenConnect.WindowsCredentialProvider.dll
ScreenConnect.WindowsFileManager.exe
ServiceExeWithoutService
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.Package.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.Compression.Cab.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
CustomAction.config
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Embedded Resources UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
FILES
ID:0000
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
ScreenConnect.Client.dll
ScreenConnect.ClientService.dll
ScreenConnect.Core.dll
ScreenConnect.Windows.dll
ScreenConnect.WindowsAuthenticationPackage.dll
ScreenConnect.WindowsBackstageShell.exe
ScreenConnect.WindowsBackstageShell.exe.config
ScreenConnect.WindowsClient.exe
ScreenConnect.WindowsCredentialProvider.dll
ScreenConnect.WindowsFileManager.exe
ServiceExeWithoutService
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.Package.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.Compression.Cab.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
CustomAction.config
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
9afde42cf03622ca680fad3c9ca851a0 › Resources › FILES › ID:0000 › ID:0
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
9afde42cf03622ca680fad3c9ca851a0 › Resources › FILES › ID:0000 › ID:0
Embedded Resources UNKNWOWN
0huhuhuhu
9afde42cf03622ca680fad3c9ca851a0 › Resources › FILES › ID:0000 › ID:0
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙