Suspicious
Suspect

400d8e0397ae74edd5d3462c21cc82fd

PE Executable
MD5: 400d8e0397ae74edd5d3462c21cc82fd
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 400d8e0397ae74edd5d3462c21cc82fd
Sha1 dc976f2e9eaa089b196e0fee615e0621bbdaa93b
Sha256 cb70ad8eaba6aae7bb80244ae9cc265988841bcf120ed865af8091290490cf66
Sha384 f5e413159014733c3d0cded9726620705177d979d1e8655a796be8615f19e75933dda4d8383bed836bcae8bf82081ed2
Sha512 1bba4ae20e8ecc91ff3a0c76a82875a7923ff1acd649b3ab3012c74b3563f6f33d3f9a5030462299e82497eb2e899cd7050ae88d6697a562d7a00993cea189a1
SSDeep 49152:jnBnREMSPbcBVQej/1INRx+TSqTdX1HkQo6SAA:DlSPoBhz1aRxcSUDk36SA
TLSH 5636E115A2E82B64E7F35FB2217B871047757E4589AB924E1760A04F0C33F5CDEA2F29
PeID
Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
400d8e0397ae74edd5d3462c21cc82fd
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙