Suspicious
Suspect

204d29d3d8d8df9dcb341786a287d5b1

PE Executable
MD5: 204d29d3d8d8df9dcb341786a287d5b1
Size: 3.61 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 204d29d3d8d8df9dcb341786a287d5b1
Sha1 95d12f47b2783e2b258927cb4c97e8e4c434efa1
Sha256 f7bdefdccc2e200bbb52f6e05b00afbcd5bfa1ab536876950824031043373de0
Sha384 a7edc27f04c03ddd93c078c256b05a998593ea7ce42e3d99041645acb84b6bd11d17a59757e7348a5975108d97ed66dd
Sha512 5f94c8403ef91fe9b23fce5b0399d97acd18f6247eb3349d3e997b2f02bab263e74200104ca4b6908809b5f76461d9f208b903bc70c9aac7402ce1668218f2ce
SSDeep 49152:KusLjIeQtNZmD3l8+ovr30w/He8kMi1jYf96kFxU+vtO8O0yX7Oth8AWu1JUHHsN:ZwkGD3l8+KzV4u8kFxNVO0yLr+mHGjZ
TLSH 6DF523BB3BCA2C79C05ECFB2D586706D306D7B9287B84C113AC85D4E2E12625EB36754
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.q=~
.KsB
.{Z-
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.q=~
.KsB
.{Z-
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙