Suspicious
Suspect

36bf1b908cd8e5e8ce9b3d88f716526b

PE Executable
MD5: 36bf1b908cd8e5e8ce9b3d88f716526b
Size: 18.43 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 36bf1b908cd8e5e8ce9b3d88f716526b
Sha1 e4f86b26e3968f234ee40f5be296e3de208d739d
Sha256 b0b6c3be5ea20c257e55a56566ccc46a9367c5886e2c9be0478df6101bec256d
Sha384 a20ec8a0f8f0b04c9587181652640bc437185af9f79e5a0ce13ef0ef258ac56cddb43ffa3bad369303f648b1feb9bdaf
Sha512 bb05aaa7e2f2e03e9db5ea856e141cbf6bed965e55c8c9861675766b8872625703dc88404c779aaafb94f336cd12c6f4e464da0ed0f78fc75131192f7f4cdf56
SSDeep 384:8wXdaOTfCrauAPjWzXiaaO3pjr5Zzr2zOAKFYzZngLW:80IOfCrauDzbBAMY
TLSH 98823B27EB8A866CFC10C4B882B79F73F167F446A516F30A97E18B292E90760173854D
PeID
32 / 64 DLL with mov eax,01 retn - sign ASL Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: killav_sc.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙