Suspicious
Suspect

81bc38164e22acd98cf0a5d5f1dcfd6c

PE Executable
MD5: 81bc38164e22acd98cf0a5d5f1dcfd6c
Size: 9.35 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 81bc38164e22acd98cf0a5d5f1dcfd6c
Sha1 58d0eb16607ac6cdfe0e4b5d6cd6cc10b6d78044
Sha256 c4bdfb0eb41ac6ea16b24ae5ce9d0a06c17f1259bc08416ddac1a08e3dd10741
Sha384 e04369d90a8be605db4fa4111efd2218d272bccfcf0769da16d056685e1bffc44180fca91790449af0de42f37e86d955
Sha512 1c958696aa0b9027cfe0f0b54e8d9c334ea8d0445c566c34d637df5d898734504cfa69516a1302e50fa2a8a4e11d1f177e7e4408885ebf16f8800a72c8729de7
SSDeep 196608:+p2t8q219RyqpGLyBvQyGfdL2g+2aeEj/i74b14ghyYG4CFItRu:+pHtRyqswSZJ+2ZEj/isJzCFItRu
TLSH B3963312736351F0CBF987728E5F8B2BD5A2D9855B885E87D64B4E0F2FAB051120F4CA
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
clusterinfo75.meta
scanner32.lock
[Authenticode]_98089d02.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
FSWEP_TE
.rdata
.data
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
VMWEP_TE
.rdata
.data
.rsrc
.reloc
[Authenticode]_21b75f90.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_9c9ce899.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.00cfg
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_651cbebd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_3cf0cb8d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bf3dd1e5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_00c4bb16.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_ae13dba4.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Overlay_82478f53.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
ID:0005
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 2secondary ignored: 6
bin 6

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7z>pe:dll
Shape pe:exe>arc:7z>pe:dll
3 nodes
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_82478f53.bin (9159529 bytes)
clusterinfo75.meta
scanner32.lock
[Authenticode]_98089d02.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
FSWEP_TE
.rdata
.data
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
VMWEP_TE
.rdata
.data
.rsrc
.reloc
[Authenticode]_21b75f90.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_9c9ce899.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.00cfg
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_651cbebd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_3cf0cb8d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bf3dd1e5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_00c4bb16.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_ae13dba4.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Overlay_82478f53.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
ID:0005
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙