Suspicious
Suspect

436a5af7a20296b3f8c4f80d4972c37f

PE Executable
MD5: 436a5af7a20296b3f8c4f80d4972c37f
Size: 3.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 436a5af7a20296b3f8c4f80d4972c37f
Sha1 3ab8ee19bc003fc51ab11cad2e57554370a875aa
Sha256 de96826e222c8e9927b271c01ee6f13b25eedb28da40adb6dec7e8fbdb4355d5
Sha384 c6bbd91f07bccf44091bde9b9e131ee5400579db0ab39872f560bb5e4b2e53ce6f315e0754ef9a31ea6997dcf02dfec0
Sha512 91cdf0ed83862661e8cc5458904126ae623612b18c20ba97e7b686d3eb1e0dab0c1084e8616208e311e5156a2a9d0711f8779ae0398831bd24fca603a0a531c9
SSDeep 49152:xx7XN8ud6USmH5uBDN9nyfpELdCeApmcbHPCDk1A+HUXUSsfGRGBFfDpXYN5O:xxvdJ5QJByG0FAoHKZESMnPDlYS
TLSH 8BE522957D9279B6F033C3A35A8360BD702A3B5587B48E5E73C8AF006D6281C6C7B719
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.hJ^
.1[k
.4"|
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.hJ^
.1[k
.4"|
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙