Suspect
PE Executable
MD5: e76d61ff0b8f528fa958b514f9a521dc
Size: 12.81 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | e76d61ff0b8f528fa958b514f9a521dc |
| Sha1 | 6b610c48d11f8876b97c8bbdb6e9bf112ce63362 |
| Sha256 | 1bfb41a19de49c9c0dc63f434ff46f51ccba78e25629031bfda16e56b0f09df9 |
| Sha384 | 560b207e6525fbcad5e840050cb3cfeca97c46a0a84e84c225e6f0825ab4a4468e290261f43b338207ede3e65f0295c9 |
| Sha512 | e19d06c401c4d45526fb74abff5c1135897efbcc672f9d477fa37eb3bf77e4d49325fbc77d95b54424a97f36d11c296dda7f0918cf0b343e941bcaf0e3c8c9c0 |
| SSDeep | 393216:V2xiFxbwpaNCl2xiFxbwpaD2xiFxbwpag2xiFxbwpaX:cUFxMpQCMUFxMpxUFxMpmUFxMpA |
| TLSH | 37D61211B3D6A5B6D0BF0639D87982A55675BC058B62C6EF53D4B92C2D32BC08E32373 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikonVC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 2secondary ignored: 10
bin
9img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>pe:dll
Shape
pe:exe>pe:dll>pe:dll
3 nodes
Path
pe:exe>pe:rsrc>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0xC35E00 size 5688 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |