Suspicious
Suspect

8cbef6881dc0e6869634c1c719220912

PE Executable
MD5: 8cbef6881dc0e6869634c1c719220912
Size: 3.6 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8cbef6881dc0e6869634c1c719220912
Sha1 8edc94d8b08d8d8e9d4c9a76303260230ab518e4
Sha256 9b09f24903d7f94aeeb26b25c495f256692322a99e650fca4e886fa90c94b2dc
Sha384 dfa61b4a77ca3e5a56cdfab126cf36c4f165c6855d45943df8dba023ec357735fb5c9b511d6efe3671470fcfd4a2e28d
Sha512 71bebd668e60fcf69d0f58a17e30da565855cd76f0088f616e54eaee8a7652dd03f282da103e5d9dcbca5c8899697c45e278a24e155296083a5dc61849804cf1
SSDeep 49152:xEE3SJtSYiPg/YR8EmoVEUkwfSY3kI6C5e9dS7cpN9Mzi4FqDHOP2Q7/DGoqcdM:RSbx4WYO+E8fS4kIRe9dSEN4SH4nhD6
TLSH 5CF533296193C26CDB300FF0C3D957A635EEA75612DEC951306D6B7253A08B69BB8C0F
PeID
Microsoft Visual C++ v6.0 DLLUPX -> www.upx.sourceforge.netUPX 2.93 - 3.95 (LZMA) ASL sign UPX 3.02UPX v3.0UPX v3.0 (EXE_LZMA) -> Markus Oberhumer & Laszlo Molnar & John ReiserUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
UPX2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
UPX2
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙