Suspicious
Suspect

6d20dd659ac64563b3a08e5ee6cca39a

PE Executable
MD5: 6d20dd659ac64563b3a08e5ee6cca39a
Size: 574.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6d20dd659ac64563b3a08e5ee6cca39a
Sha1 06a6502d3c88b9c571d086fb046dfefd3afdc497
Sha256 da9087854e915a953fc6bd966efacee6475f9ef7cd93116bd3a3a2329fc34377
Sha384 ba3d8f522b60fa16b07bc5cd500d3806c765262093eeaab66b5ecec78d44183c041e26c1da1214ccb4b30201890c37de
Sha512 dc0d481de41e4516ae892afcb3fdb35dcff29b95a50a2d1a8fd6e9995e57be5f990daa3375e4acbb02ae9101b5f70f35b14be452cad6f1b028b5f5b67c154a92
SSDeep 12288:3u6ElmuAVqAasYg2U9j42VQTJAyxBlDetAqxSv+:GlPA6gju2xyb2
TLSH A1C4AE03B580D4BAE17201358E65DB65977DB97007A11ADFB3D00EA91FB12C0FE3AB66
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙