Suspicious
Suspect

0b9bde384dac136914f21b8e5483c409

PE Executable
MD5: 0b9bde384dac136914f21b8e5483c409
Size: 19.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0b9bde384dac136914f21b8e5483c409
Sha1 25e750a10bc1d263e969d962f567fc55fbceff44
Sha256 2db23dbabf20814d496c61778c178ecf7a0da76f199f5476f45b4bbd650a4dd4
Sha384 e6f2b9445311783d168515c87e5df31f34dd23ee13471d3dd4b96a970415a6be5d6bd8330dfefdc0a2a90f95564b9102
Sha512 2e1693d52bcf0da6940180380156c216cf3570c8b7bdb16b46f01bdc0962992e9c5352dccec5c250c8f267d723122795a2415751f14e16a0eb717ebef12f3cb2
SSDeep 192:/V7qaCF6Op1t2dobVXujRDcBaXWQjwOT/2dn9HysLn3WF8qa1Dojjgi:5qaCF31cix+Dc4zjInJ7LGFF46gi
TLSH 9292D83FE31358E9C506D5B845FF3733DCB139B385A6A32E2724D2B42E106A46E6E610
PeID
Microsoft Visual C++ 8.0 (DLL)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.CRT
.tls
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.CRT
.tls
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙