Suspicious
Suspect

2673666c815880e365df72f845af8931

PE Executable
MD5: 2673666c815880e365df72f845af8931
Size: 5.26 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2673666c815880e365df72f845af8931
Sha1 25620cdbc59e173d174914458bc77d12eea3ba55
Sha256 5d66aefd528ecd9fbd31bf6def4d9f045cbbfd237a3e5e565e9a26feaba45837
Sha384 f68ffa4dc7d22d72c6514fde90c19ccf6ecf10637faaad9c42a7e87ece556977a8b7cf68e02f7b0b27af95369939f7cc
Sha512 32612ba4aad09b392f1986ce67c8c81d0f4803eaf022c67d1133ac22c7dd13044a93cf660c0049be73a9a3ad090aee158a1688d6077954f06f09bfeeed689faf
SSDeep 98304:Yd1hcPuCxywWXozx8q80RRp19wm3jxx3bhpFZ2VNGduxQ5HSb4YDggsZLqUra+CV:Ylc2ElWX0x86z1t5hrZ2VNorBS3Dgg8Z
TLSH 763633922AC651B1D499C7FC424770ADB33A7B418962BD1E3BEC0E488F57B25953E3C1
PeID
FSG v1.10 (Eng) -> dulek/xt -> (Microsoft Visual C# / Basic .NET)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.n%A
.08n
.UoS
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.n%A
.08n
.UoS
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙