Suspicious
Suspect

97b8d100f2141dc901109da036d8a08e

PE Executable
MD5: 97b8d100f2141dc901109da036d8a08e
Size: 10.74 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 97b8d100f2141dc901109da036d8a08e
Sha1 7a1ec410e9006c2f04e84aeb0e59380416e40271
Sha256 59f4e98bf1b9743607390bb23d3c4c4a84ec3d83328a03c5a5f702a8085ab451
Sha384 f3c257dace6f55429a61d0f5db4fcd5cb0ae9754becb77d97997e861f7937a00e02bf1509f3032365c664ade787d17dc
Sha512 b6721d2080a2bc8a2732ce5383a1bb2b184ccbac6829987a1372b57813de4824e0b1588555671fb6e5c0b57d86cb3935e0a08f2c6f937f7bff647843ec6f9f88
SSDeep 196608:8ETW9iCYz8dotA9Lx3sfL1VeIgn63X+ObkbptDfpYN+kymxbCH:8E4xBvLx3sJQ6XbktSxby
TLSH 5AB6239D218033ADC01E81319437FD89F2F6951D4FEADAEEB1E7A6C027BE811D505B4A
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> Vaska
Overlay_91504c5c.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.tls
.rsrc
.themida
.boot
.reloc
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.'e?
.ZL
..g)
.reloc
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_dac9c7ea.bin (3741716 bytes)
Overlay_91504c5c.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.tls
.rsrc
.themida
.boot
.reloc
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.'e?
.ZL
..g)
.reloc
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙