Suspicious
Suspect

db692ee7a63a7b322174863eb96c09a6

PE Executable
MD5: db692ee7a63a7b322174863eb96c09a6
Size: 3.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 db692ee7a63a7b322174863eb96c09a6
Sha1 7c39e2246f4915249ba2156c2d60e9042051c50b
Sha256 5874519a4bc619f535e2a4d8cbc14a5f6d938ed0a23975367ac36e23c08d7fcd
Sha384 b35b7a7957556ba7fc0957ebfcf611e90b5b1876bfa2aff4085732abddb373951938a851b04bd83614b307641a6ea5ae
Sha512 6928eabdb65c31dbbc30e529619912f2728a93ab41de45b14669d193aed67bd154311cbb38db6057dfdeb293847eb1647ba7c52ab9c3600f6e6fc2becd37e807
SSDeep 49152:sy4Kv0VptqSpzdY1555eJc9BrTU28sqQ1jtRLmx6kmrRWfIQn2+:s1Kv0tqSpor5eJcbrw2D5j3LI+sB2+
TLSH BDE5336B42163517ECE745FE25B489E0677C9809CFF783C80EBCC59349BB9EDA2914A0
PeID
x64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
[Authenticode]_8e50c757.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2F7A00 size 14952 bytes
[Authenticode]_8e50c757.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
.themida
.boot
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙