Suspicious
Suspect

3aac95680a2b0552caddcb46303c7087

PE Executable
MD5: 3aac95680a2b0552caddcb46303c7087
Size: 4.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3aac95680a2b0552caddcb46303c7087
Sha1 bae0c6968e3ee104a59ec10875685db81cecc385
Sha256 70f775cdcbd1dc33a8fe195c3d9edd702b3b6d2f226a049d7cefc8e7cee3163b
Sha384 e4ed516c29fdd7851be3f1f9cd9ed58597ac9b7d42f8c943fa9956c6e65290b4be37aa62809676b21160cbad1210071b
Sha512 08602463d4989c0af2d5cddf6003af98bc5b34897be0e69f3fe3facc4f2bbf8286c76e489f8b7764064ed86cfe0375616b301229fefcdbddea90b354064e282f
SSDeep 98304:OHoDw4/8ZTRcua/Y41kdDuHtIK5hECn6O2+DJXfJ:vxkXcpODuHtIKTEmTJD9x
TLSH B016337D4CC8598DC89FA7B7C9EAB697A5A8365AC2FC68CCD063FD81D8117234300D69
PeID
RPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙