Suspicious
Suspect

45899f8f753e57ded07eb20ca57be0f1

PE Executable
MD5: 45899f8f753e57ded07eb20ca57be0f1
Size: 8.76 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 45899f8f753e57ded07eb20ca57be0f1
Sha1 c714a73211957aa0c71defa91d4d6beca8e4abb8
Sha256 d44ff00fe9552510aefbf13c4b986dc094b5aefcd099fd3d7ad6dc816968a50b
Sha384 53edf2fa453242ac78776b695e85003758ebe25235e641a109f56169b558dba6d7971be6fee5af981ac855ca4c8f0ffa
Sha512 f62c13f9ee562153f95a73856c8df0a2df91a90ffecacb99d46c00814329cd85e379626309259ca7546b4776437b80ec51ccbb64158dbe73bb98aae4bd500952
SSDeep 196608:S+mu1iWy7DOesa7jxatMRlrIM31bxKyb0R5+x9CT1pf3:3m4YDO/a7jYelXldq+81p
TLSH AB9633572D9B6DEBC7B866B86C8E06336308C78D08F487DEE5A5480654335722EB42DF
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Overlay_d7f96723.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.imports
.tls
.rsrc
.themida
.boot
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_d7f96723.bin (18824 bytes)
Overlay_d7f96723.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.imports
.tls
.rsrc
.themida
.boot
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙