Suspicious
Suspect

5801382ae3ce2e897245e9698f641ca8

PE Executable
MD5: 5801382ae3ce2e897245e9698f641ca8
Size: 3.42 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5801382ae3ce2e897245e9698f641ca8
Sha1 554251df76b0f387e8c288ba01433be7d3ccc896
Sha256 5693516606e4593095480afa2d0d2f8f7740a73f2789bf0d549fece3dada9d1c
Sha384 2c9bb72a50c35c8a6998fb42adb98057a2d9e15d6617b8751a0a2f736b658ef15770f624ed8fb6693b1390fe53a66c79
Sha512 2e56b93ad23b4c3f4b4cb57f6ba5a57259974836c4814ddc896957b255eaf5ad961b6d5ea99d436120a10c9aaa763a57f0152c5bbbb00549c14dc989d1742955
SSDeep 98304:cvOityjtyH3BfOv62zgotKjYofINcMN0vfgpreyP:zit+tSfG62zgbEVNc5faSC
TLSH FBF5231DD7A844FDE0B7A574CA924C12E73ABC4A4771E78B07D4B8521F732909A3AB12
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
MUI
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:007B
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
[Authenticode]_c1496337.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.fptable
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1024
ID:1024-preview.png
RT_ICON
ID:0001
ID:1024
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
ID:0011
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1024
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 1secondary ignored: 5
bin 4img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:rar>pe:dll
Shape pe:exe>arc:rar>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_cef838bf.bin (2716132 bytes)
Info
PDB Path: D:\Projects\WinRAR\SFX\build\sfxrar64\Release\sfxrar.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
MUI
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:007B
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
[Authenticode]_c1496337.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.fptable
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1024
ID:1024-preview.png
RT_ICON
ID:0001
ID:1024
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
ID:0011
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1024
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙