Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
[Authenticode]_99782deb.p7b
Overlay_14308ade.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0065
ID:1033
RT_VERSION
ID:0001
ID:1024
ID:1025
ID:1026
ID:1027
ID:1028
ID:1029
ID:1030
ID:1031
ID:1032
ID:1033
ID:1035
ID:1036
ID:1037
ID:1038
ID:1039
ID:1040
ID:1041
ID:1042
ID:1043
ID:1044
ID:1045
ID:1046
ID:1048
ID:1049
ID:1050
ID:1051
ID:1053
ID:1054
ID:1055
ID:1056
ID:1057
ID:1058
ID:1060
ID:1061
ID:1062
ID:1063
ID:1065
ID:1066
ID:1081
ID:1086
ID:1089
ID:1093
ID:1095
ID:1096
ID:1097
ID:1098
ID:1099
ID:1100
ID:1102
ID:1118
ID:1124
ID:2052
ID:2057
ID:2058
ID:2070
ID:3076
ID:3082
ID:3098
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
Info
Overlay extracted: Overlay_748984c2.bin (156504 bytes)
Info
Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_0035356a.exe
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙