Suspicious
Suspect

41a65a494ba9b729e6fbf744644004a6

PE Executable
MD5: 41a65a494ba9b729e6fbf744644004a6
Size: 2.43 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41a65a494ba9b729e6fbf744644004a6
Sha1 e7c0c06606fd8bfb1c14f9ebd7a28349e659b418
Sha256 273c96eb5d64f3a07e8e741ac70c64dfb375f73e478bdf751508f033a9a36f3b
Sha384 46d916f5bd5cd73a463cf6d96dc841a76ab7e0d88049f9221431b69d21a4a419e4c6cdc0a91d09e6c820b9af2d0e2d35
Sha512 dcc699a1a466396427f7336e0e6605b41295918d27b878c4442bb8862736763c52c088cc9a0c291b69372c36fe6abe79ad31109be47eaa48f6e096bb497b140b
SSDeep 49152:jnRnnMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnv:D1nPoBhz1aRxcSUDk36SAEdhv
TLSH 24B5239931BC81FCD106297484B78E22F3B37C6A22FE5B0F9B40457A2E53B56B750B52
PeID
Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
41a65a494ba9b729e6fbf744644004a6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙