Suspicious
Suspect

febd3131850922ea9fe5f8422a0f01bb

PE Executable
MD5: febd3131850922ea9fe5f8422a0f01bb
Size: 312.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 febd3131850922ea9fe5f8422a0f01bb
Sha1 f4d67b2adce7e7bd7b7aa393aa0eb657e92dd91a
Sha256 57cbd4dbc9570fd0fb912e19edb86e54f227b2dffe2f5f2857fa11ae22e6779a
Sha384 49d927a3d6d41a943cbb9b4ddd09bcb45e0c61e44d56761c05e5a544700d1c3b9c13181d12569e532991cf16ecbb62e7
Sha512 38ea9ed172231c46ed7409f3cfe6fe2512dfdd5f5709329d1c446a29605db99a6fc971d9e12f28dc9064e7bc2333e62dadfd87655e390ea172c30c702092a360
SSDeep 6144:ymlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9v:R1iw7gryNkSV1hy1Z1u2JLu9v
TLSH BA646C11B9C48432C673383147B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_a8fa284a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11488 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
[Authenticode]_a8fa284a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙