Suspicious
Suspect

df2c53a9224afdc652e6eed0d1f796a5

PE Executable
MD5: df2c53a9224afdc652e6eed0d1f796a5
Size: 4.7 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 df2c53a9224afdc652e6eed0d1f796a5
Sha1 012a3c42b198660e828bcece431aa3af92c20fcf
Sha256 7210a8a8a01c36d0e5ab7fb1f474c8a4832379eb51c2a5139e47671f3299da5b
Sha384 7f9304e4fa07b913bb8ec3f474b63383871d42148d12fc5090befb067164c795114661cfc20783a56792e5df9c2ec3d0
Sha512 4919085185998575588521d2313a905dd3f07660308b7cfadd50f0974e569efd546ef41369ac643bc14c3507e36c68b83ca8cb1ee2ae241d885b904488dbe341
SSDeep 98304:I/vcwEZaJLusgWYJbKQv4CV9+3F79lxVggKps:IndEZacF5JbKEHV9+flxVV
TLSH B826232D634751DFC72B4230646CAB61FA3E9E686098D93AC295F07F7DB1D2E48C52E0
PeID
Private EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikon
[Authenticode]_874f88f0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.eh_fram
.pdata
.xdata
.bss
.idata
.CRT
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x479EC0 size 1392 bytes
[Authenticode]_874f88f0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.eh_fram
.pdata
.xdata
.bss
.idata
.CRT
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙