Suspicious
Suspect

0b8d2538864e7050887c483c1e9e68b2

PE Executable
MD5: 0b8d2538864e7050887c483c1e9e68b2
Size: 7.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0b8d2538864e7050887c483c1e9e68b2
Sha1 f9885e015255dd598eb7d576a64dc303a1d57061
Sha256 933db3f2d5669b2e1c25e3c97452bb3e5102cd4e0e6b1eb333b2db3b50348f19
Sha384 a3341595009218822cf2a2aeb276cccfbe24638706f82021a2b846aa9a1f1892d46df4850d5596396d9549521ba6e60a
Sha512 88063baac0e1f23bf7257402dd64cf8b8f1bdc7ed8b7e8d9bb564077a2034717d09b5422ec8e455ab99a665a09a129308ee914c6986b819bc8eda424dda9daeb
SSDeep 98304:tYyC5NLUC6SrjYzjFKdUDjbIS1jsUr4AgwFKz6bfcNDZu7ySj3+QEUm4pxB/9DS:tYs7F1fmY0R8jJEUZlu
TLSH 5C662943E6A290F8C16AC175835A7633FF72BC4D44327AAB5BE48B312E61F506B1DB05
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.CRT
.tls
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.CRT
.tls
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙