Suspicious
Suspect

1ebee59f048eb41c27e31b123fb4ae39

PE Executable
MD5: 1ebee59f048eb41c27e31b123fb4ae39
Size: 3.02 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1ebee59f048eb41c27e31b123fb4ae39
Sha1 f34c702f36922cd89b7c237d855a3f92e91a9fed
Sha256 efd0ff7418273eee3e90781e979ebc49351b8d3e34ff060dbe21d3fbd0522cb4
Sha384 429d05222c1f3ffb925805653ef1c53964574bf4fc43fe42e172990f6f22dbbe954692aa7e26f87ceb86453f63af5560
Sha512 d6881feae1537a6e8e4377003cb5f146c9e4e45059d1a906610be3bd8e5e1186c1169d5c1090a4ea7d5973dc798769940eb5f36565b6fbe3f5f05b754a2bdb01
SSDeep 49152:N/8TI7qHoAaJr9CQIhnBROGx0lTxb6rD8J08N8K9J9+L8uFRKTlHHgVkySv5vVwO:thAmCQsTOjrva860Cw8KTJHJCXnK
TLSH 18D5228DBDE27271D43BC3BB93A360EE71293F5286A49C4F35D85B00AE525242C7726D
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.QE]
.21:
.pLX
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.QE]
.21:
.pLX
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙