Suspicious
Suspect

bf790247126f769949ef29da42157fe1

PE Executable
MD5: bf790247126f769949ef29da42157fe1
Size: 4.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bf790247126f769949ef29da42157fe1
Sha1 1194f5feea7604c1889346c077da7a81f6e1194a
Sha256 5d95b8284f79d3869ccf3ec5e3dd337cd7dda19d4eab8683b9bfe07a2187ca52
Sha384 6c2e4c4cf6b4f2909065964b1a8f6438fd5c4e5300235962e1dee0345975dc34af88571780a17eafd45e6fb67a16bbe5
Sha512 d33c3fb2a599336f4941a4fdd545e46dac9f5767d909ef63c630af7d23543d1a6fc10133271628bebd53b9bdde4469ff47111558d36429e255899790c18294ee
SSDeep 98304:Wg1LUb7IpQJ776qXVtdehQNNPRMhneJaGzm:Wg0Ipa7uEVHeyZMh6zm
TLSH 0416332924D0542BDC86B0F7DCFB6E20485B016D9597B7EC3C9F8CCA36243AA197D578
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0065
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.rsrc
.themida
.boot
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0065
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙