Suspicious
Suspect

493b29207ea312681517d01af085f38b

PE Executable
MD5: 493b29207ea312681517d01af085f38b
Size: 5.25 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 493b29207ea312681517d01af085f38b
Sha1 844f9a0334c7790207f8e96b0f2a406107df2591
Sha256 5eb7c9cbdf4c3fbf69aecf8237bf2be1014bbcc90e4d9908473415cf812d423b
Sha384 b70663bf19e392b446a8654ff2c83d49750235bb2ae25f8a3a563d87ff5b09063e45794d8f7c2278f759fc8fb58a28c3
Sha512 b5f859e6026cb5a62673785a2b23a3f786f94f2eb8c917e253e14f2e92129923425391106e38f66d6a9bebb1422ad6afab523094c1601f858e506e921a57954b
SSDeep 98304:5EWX7q8zfHFHsvnYb96TXuqfVoeov8wlGKx1aU9R9uVjfhPc0LFAwjyq:6m5MvUzq9otv7lGKvL9uRfhPz
TLSH CF36334B5E866071E46AC3B88503343EF23ABB914AB0FD4F35CC95958DD7E18A97E381
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.mXR
.Laj
.7dV
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.mXR
.Laj
.7dV
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙