Suspicious
Suspect

85d1b49834187c5ab0e51495726e09af

PE Executable
MD5: 85d1b49834187c5ab0e51495726e09af
Size: 2.98 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 85d1b49834187c5ab0e51495726e09af
Sha1 acbc25d4e977eefeacda0a5113afdfe4eb39ef05
Sha256 41eaec2f03f1db37dd8ae8298b3bfdcc7930bf080723dadd1b43ca16bdf124fa
Sha384 2abc5d607dea0a54671277a8f22f64e7e811bbb65393ba215f8ad30a7ae5e693548630a4fee490d91df8eefad11267c0
Sha512 d3a19c152a2e4d3600103cf4bf647e602057ca72068987b6edae1ee6ea41dc6de3e13640d7730040388709993eb174a39b88f648359476dbfef6865e58ef836d
SSDeep 49152:cGLi+vMYILde6s0dhLcjq/ZRd17WP/BmtjBbamRHjp2QdAZOH51rrf7PBUoz+dCZ:cei+UDcTkhD188vjIQ15JrfWJIfLz
TLSH 20D5238AFDB24A76E837C3B386D3A07D702A77580AA54D4B33C877405D629182C7B779
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.=QQ
.xl3
.(Tg
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.=QQ
.xl3
.(Tg
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙