Suspicious
Suspect

cfaa9eead8f27ecc01803a5eb9fc463c

PE Executable
MD5: cfaa9eead8f27ecc01803a5eb9fc463c
Size: 9.2 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cfaa9eead8f27ecc01803a5eb9fc463c
Sha1 e8b34ffdcea5490f5ab87ada12301a31cd8c0c87
Sha256 a7b5e81ca69f663e63562844a11a261eaeff5767f16702d8b67dbfac01098067
Sha384 7459412ca9534a2afcf7d7a3b5025e5a2b6c22f6ffc6245ae7c465adf235c9db4eaa85a5f168be9588c7dd2e2b2acc8a
Sha512 1b5e3030e979655e48a57cbb34fa7fb377ce7b19c2fc3c1241834582b674068bbf6b54d5549a896a54c207be1a079acd2344d7bb5f7d05e61d57224d6b8b74d1
SSDeep 196608:c06ngZMtEk8WBaW61sHLjCGAVIQoMP5xXjaFcQB9aOMHTpzu:cpng+Ek8WcW61GChH5VaFlCNzu
TLSH 40963391BF5285FCE1A2D636C868421444563E5C498FEBAF3098FB277AB31810D76F72
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$mn
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙