Suspicious
Suspect

1cb57d209a7289f546284cdb49fc99a2

PE Executable
MD5: 1cb57d209a7289f546284cdb49fc99a2
Size: 5.73 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1cb57d209a7289f546284cdb49fc99a2
Sha1 c33576defd0531151215a5ca1ebc089fe29c37dd
Sha256 c19a50080f76018e266bcf06d162be2770c55be4d85dddcf0ee851cf761173ab
Sha384 2f533e053369d5f564b9ce16c875af67544606b06aa0287692c28fc50fc1c3721a0daf9892e1d1d778c8d2659be20324
Sha512 dc7a17f71800ff727a618fe853186b649f52afa6f0af76440b55ed739ede38047a3177bcaa20b94c4cc22bff2895a970a656052046d1e233094379342442f6e1
SSDeep 24576:Z9okudfYzty9M1NNJtFqlMsalFhV6s7J6g20h77YjKDWLsC4X:RuAeM1jJ6sFwg2097QSI4X
TLSH 69468E70E2E10D1FEF23D5BCE22A68D99EC995A18B4200B655F2D6FA41E15D4C34EF2C
PeID
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
[Authenticode]_263f3f13.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
.rsrc
4
14
29
41
55
67
80
91
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5740B0 size 16448 bytes
[Authenticode]_263f3f13.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
.rsrc
4
14
29
41
55
67
80
91
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙