Suspicious
Suspect

5e20bb866adb9e30cf429fb103fbfef4

PE Executable
MD5: 5e20bb866adb9e30cf429fb103fbfef4
Size: 6.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5e20bb866adb9e30cf429fb103fbfef4
Sha1 766624e6182815859b73223b14ebe53e575f56c2
Sha256 a8574e0a1fd7cf2657e94282303fc7035db223b497461d8a40d3d35c7214e2aa
Sha384 fb31e876cdc5083f822d4face89607379489419e028ca346544dcb4a9843292ed32facd845058957c7a67dd759ed52dc
Sha512 9fcf34713f292fa5f10391bdc77a4c536116e59cc3f4e06ddb49a4abbe957b20efb4056021ff1fa3ca675ebbe0854be302e76c8ea4592bf5b4f3673a0b21f131
SSDeep 98304:zBj1A8gxIe6xjonuXuJSOYjcKJnTTLj/s1ZgyU89LEuWUYbnFw:2xIey8xJOjNJnTTE1/U2ExnFw
TLSH FF56338AA58380A1D82636B08503D4FF7A3F34C78F45CED7D8D55D8CACA2ED9353258A
PeID
Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikon
Overlay_d4894eff.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.edata
.idata
.CRT
.tls
.reloc
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_d4894eff.bin (526848 bytes)
Overlay_d4894eff.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.edata
.idata
.CRT
.tls
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙