Suspicious
Suspect

9dfcfef66ea25e81a858128eada4aa0a

PE Executable
|
MD5: 9dfcfef66ea25e81a858128eada4aa0a
|
Size: 5.65 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
9dfcfef66ea25e81a858128eada4aa0a
Sha1
d3757361d9e496328b9f55ad46c4ce833a1ad596
Sha256
79334f591dff477735137892f04c94ac6de2f37e58ea2867f56862af81cef732
Sha384
dff233d16b72f2308fb6ba0fd4c2893e7f6c1d78e2c3dda98c114d7314533b2b32beb846fde9c7a1b538fe7470469420
Sha512
e27cd3f4ccb7fc602dce2f7605859513eb7d58c4a46555a73671be78ee460d5f3e08b7c75581f9f706785d4e94e28c6dc1203207c6f42dbba5c174f4012db90b
SSDeep
49152:zfRBDtJkGYYpT0+TFiH7efP3nrGLq7FVsLBe+1GVxrKlsuwGenGwfZVkVjOi8if0:Hqs6efP3rn/TYGVxz3GBwRVkGuyXOM
TLSH
1146F141B3D695B5D0BF0638D87A42A65634BC108712CBFF57A4BD296D32BC08E7237A

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
VC8 -> Microsoft Corporation
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
FILES
ID:0000
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
ScreenConnect.Client.dll
ScreenConnect.ClientService.dll
ScreenConnect.Core.dll
ScreenConnect.Windows.dll
ScreenConnect.WindowsAuthenticationPackage.dll
ScreenConnect.WindowsBackstageShell.exe
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.Package.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.Compression.Cab.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
CustomAction.config
Artefacts
Name
Value
Embedded Resources

1

Suspicious Type Names (1-2 chars)

0

Embedded Resources

0

9dfcfef66ea25e81a858128eada4aa0a (5.65 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
FILES
ID:0000
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
ScreenConnect.Client.dll
ScreenConnect.ClientService.dll
ScreenConnect.Core.dll
ScreenConnect.Windows.dll
ScreenConnect.WindowsAuthenticationPackage.dll
ScreenConnect.WindowsBackstageShell.exe
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.WindowsInstaller.Package.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Microsoft.Deployment.Compression.Cab.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
CustomAction.config
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
Embedded Resources

1

9dfcfef66ea25e81a858128eada4aa0a > Resources > FILES > ID:0000 > ID:0

Suspicious Type Names (1-2 chars)

0

9dfcfef66ea25e81a858128eada4aa0a > Resources > FILES > ID:0000 > ID:0

Embedded Resources

0

9dfcfef66ea25e81a858128eada4aa0a > Resources > FILES > ID:0000 > ID:0

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙