Suspicious
Suspect

Installer_v2031_x64.exe

VBScript
MD5: 6298b4c940c1e0bf262085e1179200d8
Size: 19.1 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6298b4c940c1e0bf262085e1179200d8
Sha1 a044818fa82141901838f7845bdacec35da0952e
Sha256 8ca2c6237e72f889bfebceea0e6bd6ff9e45971634e2e42f81ae10210190b35c
Sha384 a7f0e35670438cfed5a953675af7eb6f9be0f796cae7fadb0eccad1b5fbe08f4ed656937b35303af6c8124933e56e842
Sha512 a79fc7154a9d2730e46a050d59f5c6b984de50f56c380731960f0ae5f9fecaa18d1fa084fcbadbeaf3afc0c934a6cc0e1456751336cda4058b31f1c7c4acccc0
SSDeep 393216:8EaMWJSyP1zq3603bKaQGfBiuVn8NVy1cwKih8/t9eWEBbgFB6qFRi:8Eabt+HkasgsgcwKihW9eWEBbgBi
TLSH 0E173336B208DA78EE0341F1F60CDE84EDD55B07A4BC7741A205D6AF6D74A82F69B603
PeID
RPolyCryptor V1.4.2 -> VaskaUPolyX 0.3 -> delikonx64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙