Suspicious
Suspect

1f1a5a7f724049e999156af33f1ac3bf

PE Executable
MD5: 1f1a5a7f724049e999156af33f1ac3bf
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1f1a5a7f724049e999156af33f1ac3bf
Sha1 b81228d2cfc4e5bf691691e6df07150d95d857aa
Sha256 48a7637f5cbd82ba0b7334abe034609de5186d62cd5a8fd486cc565c3dde68ab
Sha384 db3d8c79cfabb4168844ae59706b7cb6249448ba1e84743d2642471f58746149b30a2cd60480486b685e472b0f94bd55
Sha512 9cefe07c832f5debea3af19332c2785779db29d2e0b8691d865311195d9aac304f74782a046ea47bbe8c2a1f470f6616a3693111549f879382318e629908943a
SSDeep 24576:jbLgBbLguriIfEcQdIVUvxcMNgef0QeQjG/D8kIqRYoAd:jnsnpEKUvxcBVQej/1I
TLSH 9336125631E8C0B5C503623098B78F21E576BC2A2375964F7F904B7E2F237A1E729B52
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit )
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
1f1a5a7f724049e999156af33f1ac3bf
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙