Suspicious
Suspect

e974d4048bc2079b656426bdc92cbdd9

PE Executable
MD5: e974d4048bc2079b656426bdc92cbdd9
Size: 312.53 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e974d4048bc2079b656426bdc92cbdd9
Sha1 8784b673081074b28409d29e1b59be67b4ee91f4
Sha256 ce97b609df1b5fe98cea4d8763bbd569d98ca7494a59ab0590cc9176e1907eb2
Sha384 5abd8ed8304dd2b558abefbf3c887c49b92bbe1d15fbdf4c7e644eba89e1f5a64dd71d8133dc0e35afa1f19a11762a78
Sha512 66bf1d3829391b905843596e186a3fa3bf7a96b8852af0050e897a3efe321a820d9d5da65a3428a35964ad6a1e90ef0bc1fcff3ceea286b32a8fed6cd9e29f11
SSDeep 6144:CmlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9:B1iw7gryNkSV1hy1Z1u2JLu9
TLSH A7646C11B9C48432C673383147B8E2B28DBDB8301D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_8b2eb7fb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11472 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_8b2eb7fb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙