Suspicious
Suspect

ccd14b31feda17c5c52d9a42c253b6c8

PE Executable
MD5: ccd14b31feda17c5c52d9a42c253b6c8
Size: 2.47 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ccd14b31feda17c5c52d9a42c253b6c8
Sha1 645abc88d41c0d809a58263b32f12b9ca437424c
Sha256 163194d22f93028f5142645d44fc4a763084df5348cf3ed50d7e660071fff7c2
Sha384 e17443f8aaa383614ebfd784dfa214466d8f68885f04b16eca0092024fc4e10f27afa3435dce8770e84c65cf00e1d832
Sha512 b3848c2683122dab788dc82db4c29e7f789743d9e574aff4447c145af3da2b7a887257689e917bf9ad491870de75ed3ba799ade40a8ae1fb3eaf91ff91c2fc5c
SSDeep 49152:fqJoQYXJGa+2b42HVfx7cQgJmriR0zKiXJhuGgxeCXz:fqJoQsJGaj4237cruKcJhYxeCXz
TLSH 59B501D5E5360CE8D14EC7FCC8AA9E520C19FC95EE4004CEB422954178EA3B9CB6DE67
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Overlay_424d7ca5.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.laghab
.cimbml
.oqyimc
.jhvfml
.esaznu
.sunwhv
.lpktqr
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_424d7ca5.bin (172 bytes)
Overlay_424d7ca5.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.laghab
.cimbml
.oqyimc
.jhvfml
.esaznu
.sunwhv
.lpktqr
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙