Suspect
PE Executable
MD5: fa1d0a6bce748dd794a27ee6179bf948
Size: 5.67 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | fa1d0a6bce748dd794a27ee6179bf948 |
| Sha1 | 62d290cced859110aa3d507aa52e7ffb48ea29bf |
| Sha256 | 2135da1fbfb04479247c4268d2002059ca335b5384929093644e4896c44a37bb |
| Sha384 | 803e70bcf3f965e97fff189febd1d0239f9e4d845562225c7067e2ade5e07da7e96adf8440ff4aad8e36b9cc6aa4360e |
| Sha512 | 542792f9d0e96e816c52c3f39e09a52b86fd8b0f6d804ed35ceddf57edbf760b26082f52fc25eea5247a2c7953c78ca4fd6a97c3d4243cdcd78cd41555f16d8d |
| SSDeep | 98304:0zIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:0hfefPtHxcp9ym3nltDUJV |
| TLSH | 0746E101B3D6D7B5D07F06B8D87B4A655636BE048311C7AB5394B92F2E327C04EB236A |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12VC8 -> Microsoft Corporation
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 18
STICH kept: 1secondary ignored: 17
bin
16img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>pe:dll>pe:dll
Shape
pe:exe>pe:rsrc>pe:dll>pe:dll
4 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x54A600 size 123160 bytes |
| Info | PDB Path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |