Suspicious
Suspect

2f89f9431bd97dba2fab3cd2f02d6f10

PE Executable
MD5: 2f89f9431bd97dba2fab3cd2f02d6f10
Size: 5.35 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2f89f9431bd97dba2fab3cd2f02d6f10
Sha1 912baf829d387831d0dd450744b5cc0d5496000d
Sha256 467ed1f5cfbbb2bbb6f90f75d1b2bcd99dbeb38a65cc4bcc7bd39767a62d5676
Sha384 3a1e7720f302c088c0ecb496316dc4a7c83ca5ad4bb81edc29f94a555bfc8def97f22f6ac4962c420a1a2bf163fd93f0
Sha512 5b62e776320f44e4e1270ba7911e5676264b9229ea0a5dfcd2fde30bec7af05dc7ac3e90aafab547eaca8b5111935dfabca38498f6b791ad882fb8ba65e20fec
SSDeep 98304:2LnzhCZQXR+2V88cf4E+BWG2oLehWT29vlVVKCawyLBMeIMH8o:2TzgZQXR+2V81gnBjP3yVLZ5A8
TLSH D746339238CAC1F8E443CBB8865B757DB36E3B5249A43D5F37CD7A009D1AA18647E381
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.(4<
.+]<
.VIx
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.(4<
.+]<
.VIx
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙