Suspicious
Suspect

2221a8cd6e4936ccfe2293fc5d05e70b

PE Executable
MD5: 2221a8cd6e4936ccfe2293fc5d05e70b
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2221a8cd6e4936ccfe2293fc5d05e70b
Sha1 51288d863898e5dca5dd2ba1f7a2a544c4137ff3
Sha256 5a2eeecc6e9890ba62bdae25a8ea1451d800f347f69e0edc60814511d481ce96
Sha384 6766d4605f0feed6e99326f76cfc4bd47bb5abe848a5d87f3d639e515dc8cb0531cee402bb6143e4d51e2afd03d3e649
Sha512 708b78d572c05cbbdf9bbe86313ca4db2de09fa39e5f9e5adb12aa9ddac61fe87785458c9d5fc23d597c6d0905bec69cf3ed9d5b6ae98a43d5a35b0664c30428
SSDeep 24576:jbLgWbLgddQhfdmMSirYbcMNgef0QeQjGm:jnXnAQqMSPbcBVQejm
TLSH 99366C11A2E86B18E6F35EB1237B9710473A7E89995AD25E1324510F0C33F5CDEB2F29
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
2221a8cd6e4936ccfe2293fc5d05e70b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙