Suspicious
Suspect

PE Executable
MD5: 44a7019d8cc037255d24a04da4908f89
Size: 6.42 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 44a7019d8cc037255d24a04da4908f89
Sha1 5bbfbb88013849c667216efed34367541d36f55c
Sha256 4ee3ad4e4e7e262f5dd917322ab8a04f8d0afcfc05b3093230bd9ff7cca1a56d
Sha384 e533e4cc0775501649ba96219ff64424e43956d40f1fc2ac2f48490f1abc78d9a647ac78979cd02d945290ec5891a9f3
Sha512 0a92e42b09f081dcd05f10db353e38e52a24cd1275dd9a13067a018f8e60fa681ca9803da37de7159756933d92eb8d74b578384ba9e107b6de36be712d1fffe5
SSDeep 49152:GGtlqHIU6iyBVwASO/WAqiUvOH/oYhHJNInPllaQO6+94/9GMcKQTsVhtgwtzqPq:7+eWs8TqZeEZ9wbuGbnxJtWTQ1UnnC
TLSH 3D56BF65A9BC00D5E86A96BAC28B5227D771BD1417B007CF2B9497E60F23BE01F7B740
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
44a7019d8cc037255d24a04da4908f89
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙