Suspicious
Suspect

Installer41809.exe

PE Executable
MD5: afb3fbf55c3477ea1887d8c80a9f3fd0
Size: 15.85 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 afb3fbf55c3477ea1887d8c80a9f3fd0
Sha1 d5a9108e72d8aaacbf423fa173874d1bf3ba9575
Sha256 d7a1cbe50f85236cbcd00fe2aeb64dbe12ec5614b745a437b835fb1b9d7be35d
Sha384 50d9c8f494eaa24c718e860d554550a5b05b869cef8424960d64819487996e27ecfb24c18cd058b49b7867bcff9f052e
Sha512 dcfa8e67c753c99cb57fbf5ea7c401d2a642e6d87db77df477ed19811e0144e66f238d9ef2528fa278dd54a980f7ecec580abdfad162c9938b2f15ca2e5f4547
SSDeep 196608:x9QQM6MvAaiOZPt04ZY5TrXXqR+W44DfXb7uRapVGlPe04gemUIIgao2mh86wBt7:x9Q0MUKF04MzaR+qC067shc8Xkb
TLSH 8DF633A52C1800DEC8F2DF382E72F7D56E411FE9B2887D15E668FBA60DB11F426495C8
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> VaskaUPolyX 0.3 -> delikonx64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙