Suspicious
Suspect

5aae2e9e6fd087916fd205ff29d703ed

PE Executable
MD5: 5aae2e9e6fd087916fd205ff29d703ed
Size: 645.64 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5aae2e9e6fd087916fd205ff29d703ed
Sha1 f62c6296e9b21213ae21605ea2412027f300a032
Sha256 271aa48e3bea2f472a6039f0bca6e70abfda1c5abdfcccdfccd18e0dd515b15e
Sha384 20982d4011cfa31dbc583b2e96306f6040c20fe16fc18b91c6ac6ec210d675bbef9b926588375dcd7c10ea9f26730aaf
Sha512 446dc147a01abd1d7b4f9197c5edd43a0af12374c3dab0ce50cacd0981031ac51e80f23226077cea52d8fbfff36d8385d8275c2dcfec1f72163e004cde3bc6cd
SSDeep 12288:MANwRo+mv8QD4+0V16/C6ucY3S0vonTyvUXwbJs:MAT8QE+kGDISnmMXl
TLSH F9D45B83F04130ACF8DA827769DB8A3AF1E55D4A1D435841A2B53F00FFAE6D653C469E
PeID
BobSoft Mini Delphi -> BoB / BobSoftBorland Delphi 2006Borland Delphi 2006 - 2007Borland Delphi 4.0Borland Delphi v3.0Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
Overlay_9661a10c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0032
ID:0
ID:0-preview.png
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
ID:0037
ID:0
ID:0038
ID:0
ID:0039
ID:0
ID:003A
ID:0
RT_RCDATA
ID:0000
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:0
RT_VERSION
ID:0001
ID:1049
RT_MANIFEST
ID:0001
ID:1049
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_9661a10c.bin (267274 bytes)
Overlay_9661a10c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0032
ID:0
ID:0-preview.png
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
ID:0037
ID:0
ID:0038
ID:0
ID:0039
ID:0
ID:003A
ID:0
RT_RCDATA
ID:0000
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:0
RT_VERSION
ID:0001
ID:1049
RT_MANIFEST
ID:0001
ID:1049
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙