Suspicious
Suspect

c0c6f6e0731a319cc92f90ca789dcc3d

PE Executable
MD5: c0c6f6e0731a319cc92f90ca789dcc3d
Size: 312.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c0c6f6e0731a319cc92f90ca789dcc3d
Sha1 6dcdc64f2485722a41c40695daaf6892c2c9f7e8
Sha256 e5c9ed91eb09773e30971c76bdff83f08be5ca5ae251ccb6addc72192a0b1529
Sha384 d12309b92e8f968d7bfd05c8bdb3b717f0f454750953e9c3c38a769b7a285730863230900c826ed3f45e0d5647bd9b25
Sha512 78e89fa16e7bae13684dc02c98ede71087a62d090c265194a8fdb13d28ae26cbaf78dc33798a57f3ae3ca2f19bc2252e9fcfa3c29ebb8dfe5438b27baba22264
SSDeep 6144:amlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9:p1iw7gryNkSV1hy1Z1u2JLu9
TLSH 3E647D11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_e8c261aa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11480 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_e8c261aa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙