Malicious
PE Executable
MD5: 4ae6397d898c18b1356dedcbe225e639
Size: 22.08 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4ae6397d898c18b1356dedcbe225e639 |
| Sha1 | 8ddc91dd3c92113e654815c91c9accde8170dde1 |
| Sha256 | 83554baeeb700815f9b6492584a1b1a40c64f752d1ff1a67cde079ad524b008f |
| Sha384 | 610c381f2c30fb9b7d68bdd5bea6937961d4dfe91c2641308fafc92c79d7fcc78f0d0d5d492d16bb04da2ce9364a5fa6 |
| Sha512 | 61a02edb4dd147e63ec7adea49d75e6adf7c6384134d8b833006cde6eaba60c2c3a89b32ab8c1afe0bfd39a96d4480a860bb4333c58943592f58670c4febe5ca |
| SSDeep | 393216:WBuh88jMY2LToqSLIGug8C+U1C39YGOFEEV6DnyPQTKH1OZVozeXo80BkpiQv8v:WSwYOOvu/CmY1FE1jWQTY5C0mRvE |
| TLSH | 692733289FEDE638C19647B6C7945A34CDA908C911DC7277934D2F13EEC3A2A507B1B8 |
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 5secondary ignored: 2
bin
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
5 / 5
Path
pe:exe>scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape
pe:exe>scr:vbs>scr:bat>scr:ps1
malicious
4 nodes
Path
pe:exe>scr:vbs~T1027~T1059.005>scr:bat
Shape
pe:exe>scr:vbs>scr:bat
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_4c91aeac.bin (22010075 bytes) |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"
varhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
""
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"
varhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
""
[Uhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
& [Unmhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential