Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: e0ab2773cc07e8203a680f6339170681
Size: 7.69 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e0ab2773cc07e8203a680f6339170681
Sha1 a9c5b069aec9dd4e3608c87d187313cdf663525c
Sha256 a025f425022df0a0fe1ca8ec5e0554156a49cc2ae302b971878a6e7cc41d0677
Sha384 3484bea466f32df30054658de8c676b04d325222c9b996cd67149423752b2e95ff02609f0fcd89a2ff1187528f7bcad7
Sha512 9d8004d1122110b2f13151222cb73237910576a57230de0547e366a02b2aa4ea6114c2fc829cc56cd49303ca4d7bbaf8fc31e7a78d39fd950c897ca64bb84af1
SSDeep 98304:uQHbG3aWzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zlh:uubqhfefPtHxcp9ym3nltDUJVn
TLSH C276CF06F9E259F6C0BF5635887652917B70BC051B2297EB2B90BA382F33BD05E31365
PeID
HQR data fileMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Overlay_731ea7a8.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
ScreenConnect.Client.dll
ScreenConnect.ClientService.dll
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.gxfg
.gehcont
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
_RDATA
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1036
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
ScreenConnect.WindowsAuthenticationPackage.dll
ScreenConnect.WindowsBackstageShell.exe
ScreenConnect.WindowsBackstageShell.exe.config
ScreenConnect.WindowsClient.exe
ScreenConnect.WindowsCredentialProvider.dll
ScreenConnect.WindowsFileManager.exe
ServiceExeWithoutService
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Microsoft.Deployment.WindowsInstaller.Errors.resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Microsoft.Deployment.Compression.Cab.Errors.resources
CustomAction.config
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_731ea7a8.bin (11320 bytes)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙