Suspicious
Suspect

4943d849afc9a5b63b92a003954b0975

PE Executable
MD5: 4943d849afc9a5b63b92a003954b0975
Size: 109.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4943d849afc9a5b63b92a003954b0975
Sha1 2d6984bd5730d3562cba48ee1c29d8ff769671a4
Sha256 d5bf67f2953720d31d299ffae9ff6f0e785d357041372c3045fc0c9278e8a8f8
Sha384 0bfd68e7244c173bd49611f79ce2c59ce81431bff1e0ab0bfdf24240287d561aebebd5c09b38ee7c8e96cac68739a8bf
Sha512 9255683af1df9c51959cb3496b8252bf213cd7b0e10ae5ee391ab44d8ea66ad6d30b5896e1e03f2de4b3d9f1626e004d4334f18803e503efab17f41ce8f940b2
SSDeep 3072:t0d+/brLD9SIiUOkyJo4B7CpZg3MVPqG0:G43LD9izJoQ7CRqG
TLSH AEB35B9BA7A530F8F4778678C4910A49D772B83217609FEF03A4865A1F236D18D3EF61
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$mn
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙