Suspicious
Suspect

3cc47b90df14f11cf82c289de2f78087

PE Executable
MD5: 3cc47b90df14f11cf82c289de2f78087
Size: 3.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3cc47b90df14f11cf82c289de2f78087
Sha1 003e5ddc139c87bb8a06a54c3404e6c706d516df
Sha256 397fc2060b8bb2e308dcf498f20bbabba97128150bfff564647a6afa47f57fab
Sha384 3617e8d53d40eccf27f5ed8fec32c8c01bf237e069a06f691bf1af54cbea3ba0962eb6418daba8867a81cd51ed7a06e8
Sha512 d5af99e9070352a9e410a10933b7c70d64be0a5fc6cda812555cb604a05f28c7187d9274c9084f4216a9838d28c82b2c131c40cf74169e9b8cc68fbeeebfec48
SSDeep 49152:37lLu4MI4bWOziyKtPxRDRMEQ+yEXHdYyZHFX2bGJVGv3RDC:JLl4xG7xR1wEX9NZlX26JIpDC
TLSH CDE51243BF54A902D59A5EB598B0C3F85371FC49EA16934B35C6AE2BBDEE2C34D024C4
PeID
Private EXE Protector V2.30-V2.3X -> SetiSoft TeamRPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
[Authenticode]_d901af8e.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1042
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2E9000 size 14136 bytes
[Authenticode]_d901af8e.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1042
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙