Suspicious
Suspect

04933ea6ce91169b03d5a1dc28ac9959

PE Executable
MD5: 04933ea6ce91169b03d5a1dc28ac9959
Size: 2.96 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 04933ea6ce91169b03d5a1dc28ac9959
Sha1 e7be100d8b31f8b0c42a06c44abf8b595d0b123b
Sha256 77981cb7370daaa409e8bf4cd370177515bd0960243c3bfd8ef2b4fb2b190bd1
Sha384 d2b3aee7cc432443f2e1dfb8ac50418d4888500f9013c0b5bbc1d0424f03d33b024c598c90e98f307422667b1c7d40b0
Sha512 9c26cc51a9b56839493e40bace5bf2cb18ce8d40e09b728e018710bb34a3ba51354b83ff223fa3f2cab06d11d2ad86f62aaa90bcca3de3afede5f3fb496e8382
SSDeep 49152:e+ZFWoOWdKpuOFY3E80rIcAvH6b6Egq4MV9D8TispzRnno62PedI3BPn1swkq337:eIFWo9iE0rIcAf6GEL4W+PpVo6M/FBSX
TLSH D0D5238935BE29BAD437C3729FC5E46EB0193BC0C7754E9B3A8C79109D126906C3A379
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.Z_J
.QZM
.HPC
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.Z_J
.QZM
.HPC
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙