Suspect
PE Executable
MD5: 40c3bb25ce680409353ba703dc11ea8f
Size: 5.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 40c3bb25ce680409353ba703dc11ea8f |
| Sha1 | da808f876105cafd99d73a42de4e14ef45cfc203 |
| Sha256 | e4ec8ea01e91627c9329c2889249f2e02ca78ba5f22eb84ad24ce63e7cf816a2 |
| Sha384 | 6b0be0f77110fa43dbc0ef5ffc234a2145f5fe26e7dd0bd0c1cd47b24ca9eb961fd96b4ba3803294849f6bd392854f48 |
| Sha512 | 4dd42348a3054fb88e7b03baeb5429973223f666bc64dbf3e9e97c99dbbd1c4744b8bfcaa4a2eacbc1628f8a6b22d620e82555da0df81ca472fa8b6ecb3ba953 |
| SSDeep | 49152:jnsnsQqMSPbcBVQej/1INRx+TSqTdX1HkQo6S:DM/qPoBhz1aRxcSUDk36S |
| TLSH | 5936239D31BC91FCD10666B484B78E12E7B37C9A23FD9B0F5B844A6A0E03755BB50B42 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential