Suspicious
Suspect

6988ed538b6bd149096068e7aa46bcae

PE Executable
MD5: 6988ed538b6bd149096068e7aa46bcae
Size: 3.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6988ed538b6bd149096068e7aa46bcae
Sha1 251ecb01a393dd1f842c1b52d5b3fdca2537fde2
Sha256 9839f9ec79e7ecf2f4a58f672700f4f6a0f5efd63ec53bfe86dfccb53fdd56ea
Sha384 3a581055551a113e97704cf080682a5e96592d561aeec10a3bbd0260911c7803595403fbbd1997aae5db4651d9898b13
Sha512 1744b6f8adc0b3277ba7bead620e2bb92f85eed2afcbb93dd7f1e129745096c2874a657e13aaa603e9ed27b6aae869b302b825f1f789a32a72ceb3402a17fb83
SSDeep 49152:TKDiiORB/ria9u2HsveZyBOW5iXr6Befo02NpsCgDfbkaaaFbZSPpal:TKDihL/riaXxp402wCkfbkaauVSB4
TLSH 6BE52388B8D672B6F076C3F743A775DD71293B918BB21C9E31C94B605D128282C7B35A
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.k3t
.<2}
.R2F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.k3t
.<2}
.R2F
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙