Suspicious
Suspect

3856cf206988acc6389777fa62c34cf5

PE Executable
MD5: 3856cf206988acc6389777fa62c34cf5
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3856cf206988acc6389777fa62c34cf5
Sha1 abbb5e58bd3f2e06f2037eb39a08561aba517297
Sha256 01469b8a4aa195637983cc952ab5dac5e9b7b46091ac709f8819ef82fa4c8b26
Sha384 a50ed713bb83068f9743e70ea60c8256e5015aac91e326c0a5305af6f75b25ee746c5fb297f13c61b3cf37df707a4b27
Sha512 7ab02b3f1f5ccf030d7b9d75858c9c296d02cefe0aababcc81e8fc4c8e21ba26d6d229c8a91ffcead0eae7b526f14a7a6f1f4ec7ae79213db3f4935498031bdb
SSDeep 98304:DI8qPoBhz1aRxcSUDk36SAEdhvxWa9P5ep:DI8qPe1Cxcxk3ZAEUadM
TLSH 5A362302B7294EAFE016163CC4F3942776B67C16973B8B0F8288B71A2DF37455E64B16
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
3856cf206988acc6389777fa62c34cf5
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙