Suspicious
Suspect

89be18c970779202b181e87c95aa71bd

PE Executable
MD5: 89be18c970779202b181e87c95aa71bd
Size: 706.05 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 89be18c970779202b181e87c95aa71bd
Sha1 b8670f6e956f5f2fe6bc82dac2ef7253d093fc93
Sha256 9838584fba1ebdf51d3fcd9cb0d5461d92001e574adafc826dc3ce914f7304b8
Sha384 aa2cb08e43801206ced9b511f88141fabc85f55115bca242163618e15aaa1c0a0d3c18a3391dba354c62c2cecbd65f51
Sha512 250d53ebcd1e6d8ca975e2574b64b05ef076b73e4b321e5530bdcc43d9f6dae134197eb183b41f1f57317f23e8acaa1cd736b99ad570398aa4623a0f86a3239e
SSDeep 12288:cbJIS+LL7aTVbNMyFvImAdjT3gT46QCsANUEGORNbj7lWqUnoecL9L19AO:+SVyFvvAdQ+EGcbjxrUnodL9L19A
TLSH 27E4F126B1B69C13D176C8B88D21DA801D75BDEAAD906EC373C43FEE0E211664BB5533
PeID
Microsoft Visual C++ v6.0 DLLSafeguard 1.03 -> Simonzh
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.reloc
.ymyykzd
.kdyknvu
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.reloc
.ymyykzd
.kdyknvu
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙