Suspicious
Suspect

68cbf61ceec7cdae9e2f6db58d636803

PE Executable
MD5: 68cbf61ceec7cdae9e2f6db58d636803
Size: 5.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 68cbf61ceec7cdae9e2f6db58d636803
Sha1 0636a09e75a3741951be7ff6c8cfb6a1763b0d39
Sha256 f52133d8174ef8c037e73edcceffcafa2fe2db27b32804130a8d9f2c15359847
Sha384 32c61f11d34150b64fa61ce590be42855854c6d6a74b0af35816e83b64265da8bacfbae2a1d2e659d839e0f348779a50
Sha512 4928157d4ba8a36627e02de7cf7592680595635993beb4b3eb046a1967f5daae753fa39651a993796e05f9fa9177b53f26a5521f961327520c3cfbf59d1c8adc
SSDeep 98304:XJ+NtAq3vBHtHwI34j2fUqpoUmM9YF1lzHNZw3+Vy8u7+:XJStAq7OdqpohM9YFNZwONf
TLSH 8D3633067B10E848D65A5938EE71C7F96714FE0EEE8A939734C6BE8BBCD46C14D990C0
PeID
Private EXE Protector V2.30-V2.3X -> SetiSoft TeamRPolyCryptor V1.4.2 -> VaskaUPolyX 0.3 -> delikonx64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
[Authenticode]_caca11f9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x4C8000 size 15168 bytes
[Authenticode]_caca11f9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙