Suspicious
Suspect

InstallerV21039x64.exe

PE Executable
MD5: 44a551af59e8f76a426f249bd945cc62
Size: 15.21 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 44a551af59e8f76a426f249bd945cc62
Sha1 3b2d036e8ab48b53226af106267858970203fc06
Sha256 74c66faabbab048a567c8550d2cfb9268e61724fb58292a604d44d296777f260
Sha384 8948f21c9cc16e978200d97761262d8d5cd2a20abde796a36f6d5e698e07a5226b593bcb420178d6d59c8e0e2f22fe2e
Sha512 128f5083600d3512cd74cac6bb77d8e7b5700806c40c4d9e2e3e0fd00605856964efafafc171fd3d8ec65bfcd9f1b58938d43abded88ac76ab50dc5d6a3f3aac
SSDeep 393216:F4b+oRXgK4CjpVBWwQfgaW+L4B2tOUNKj3rpXNpJoJ:F4b+mXgKv9VD+hW+kkmzxNpJo
TLSH 5EE6339C7CC1986DD9F354B0BE128EAE15E55CEAC104871F2C873BAEF52D629B58340B
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙