Suspect
PE Executable
MD5: dcd9e924e9a72e437efaab549c158d50
Size: 12.81 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | dcd9e924e9a72e437efaab549c158d50 |
| Sha1 | c14e06782c08971fb84dd3d7e44fbe3eb0801ddf |
| Sha256 | dc02857e1b8947c47d537697fdd2f2caa8d96c0e8aa0384b8a033fab5468cf24 |
| Sha384 | 0c95fd197caaf81d4ded7838a5a75c7511ffc00af48c14e1f47db5892456c5996dd980921f27a8416a1f1ca4bebc1234 |
| Sha512 | 51bb2baad1fecaf64dbb55757b740166691eaa27146f135e15ce2c0b7a5bfe0c88a0cc5c138118de294103589fc1bd617b49f34d83712fb7b3ab232e5e779422 |
| SSDeep | 393216:A2xiFxbwpacCj2xiFxbwpaD2xiFxbwpaq2xiFxbwpaF:jUFxMpJCaUFxMpxUFxMpUUFxMpy |
| TLSH | EBD61211B3D6A5B6D0BF0639D87982A55675BC058B62C6EF53D4B92C2D32BC08E32373 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikonVC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 2secondary ignored: 10
bin
9img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>pe:dll
Shape
pe:exe>pe:dll>pe:dll
3 nodes
Path
pe:exe>pe:rsrc>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0xC35E00 size 5688 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |