Suspicious
Suspect

0195f6e47a152c5e9ac46229eb492af3

PE Executable
MD5: 0195f6e47a152c5e9ac46229eb492af3
Size: 2.98 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0195f6e47a152c5e9ac46229eb492af3
Sha1 eb2ed77945d3418d25acef6805bc033d5ca11184
Sha256 90ef4c4f1d988b2eb2154aa61b05624afd7172ea55deff3ca8961b0ad99f1fa8
Sha384 dcdffbf83524185d68b605de29fa9bfb6d02d5bb47beb9d43c4ae65efdd9f50f3cb6624f1b8ee1daca1e233f893f2670
Sha512 18aa461264f586fef0602bc3a3254079f4637489602da74a422050fda100afd974740937bc660c4976f1f358bf7a171e93f6e2660d03323858f5de08d06d5576
SSDeep 49152:0z7sl6ODriEg5N0N75Mg5xKKdw3Xcv7Bgc/ZljL9TvA2vD2GuZ0O05uIXG:C7Q6orvg5Omyxzdw3sv7BgcBRL5FbrG
TLSH 21D52298FDF60A70E836C3B34AA360AE711573844AB44D577BCD2B105D52928BCBB379
PeID
Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.#(q
.8EE
.WXI
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.#(q
.8EE
.WXI
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙