Suspicious
Suspect

d41c26764b1ddfa1ce2d5d832e0b4b5f

PE Executable
MD5: d41c26764b1ddfa1ce2d5d832e0b4b5f
Size: 9.9 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d41c26764b1ddfa1ce2d5d832e0b4b5f
Sha1 4a77fd76c44d61ece68eb178aaf7d5f292a6e886
Sha256 2f12930f0d69a16b854f4f094ee2f10d1abc007d17dfdb3a7dcce38947309664
Sha384 7551f9d477b29c607e30fe5c5603820ef7379f7a17ace0b91f3da298b42615d1028ab1e91b172aad4ddb4134124336af
Sha512 1be86c5cdc362e6ff6249001fec610a735a4a548083052fa83e6b095ff5410b238cde269808aa898e46426b79f8212929055c9b481d709e694f7824ba0401f1f
SSDeep 196608:r7HgSYk8+GNK5REapQF8plOF5sVWpdscfKRTmjDKWf0jskDmjL7jlwy:/A1OREEQ8PirxLF2SjXjx
TLSH DEA6337FEB889631E33288B698EB1D1F0711621B3721C1135AB4895DCD2316BF6B947B
PeID
Borland Delphi 4.0Inno Installer v4.0.5] ;collides with: Inno Setup Module Heuristic Mode (Inno SFX)Inno Setup ModuleInno Setup Module Heuristic ModeMicrosoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Overlay_06030306.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0001
ID:1043
ID:0002
ID:1043
ID:0003
ID:1043
ID:0004
ID:1043
RT_STRING
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFB
ID:0
ID:0FFD
ID:0
ID:0FFE
ID:0
ID:0FFF
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:1043
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs
Shape pe:exe>scr:vbs
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_06030306.bin (9830076 bytes)
Overlay_06030306.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0001
ID:1043
ID:0002
ID:1043
ID:0003
ID:1043
ID:0004
ID:1043
RT_STRING
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFB
ID:0
ID:0FFD
ID:0
ID:0FFE
ID:0
ID:0FFF
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:1043
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙