Suspicious
Suspect

492efec9fced2cd3598584cee05def7c

PE Executable
MD5: 492efec9fced2cd3598584cee05def7c
Size: 17.76 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 492efec9fced2cd3598584cee05def7c
Sha1 65ad9579d53559875199553a6d737d2070c7c34a
Sha256 2a241192ae8a7d1b9a0134f8bc6456b5d37f399dadbaaea5bfd45e848af78286
Sha384 49876571e780e2a24c6bd858b5dd7322badaf91476cd33d8566c3fa579adb10d97971ff8a13f063a62e9f155877f574a
Sha512 49919763a26ad52bb912d5f49ed2927fd30de3d4086d1837ded0f4fd95df468c2a97f961cfe2e59bbb27c53ce4880d13c646d2cfd84fa18aee73842ffdc5451c
SSDeep 196608:I8fBC8YUFgxQxCHnC5RilfnsZXBB03UE:IeQ1Kx6KitnIXbgU
TLSH 9C075941FE8B95F6E90319310567A26F67306C094F29DBE7EB40BB2AED776D10C36209
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙