Suspicious
Suspect

97f1abb216dd1d9e2b2b4b7c673965af

PE Executable
MD5: 97f1abb216dd1d9e2b2b4b7c673965af
Size: 2.98 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 97f1abb216dd1d9e2b2b4b7c673965af
Sha1 bbea5b3f29625347e44b164cdb399ec3df6504cb
Sha256 2f4348bb0f04eb8bd5f416ab396831fdf6198f74d23ebfa03a4a4bc9a0023fe0
Sha384 0997a598fe2f8b693edb144e71699c86e0a401c3f93c73f12283abb3368c5f2eda033d86b239163aa98e94ded4766500
Sha512 3c410de2358bc93d65d2f2c47c4f42c3af980a042028575e45d72cdc198f633ddacbdb3d0871bd807337ff1ad20f6a90feaafd6288741225e35c913f82bb89cd
SSDeep 49152:7UeZNer6Otn6H5NcZvHF8i9xScrzO4IKvJucvcsnucwi1qfiJfiPe8P7hrxERs0:Bb3Ota5NcFFj9x7rAgN3qKfclS
TLSH 2ED52398FCA759B5E473C3FB8283607EB0697B844A618D5B36CC1B412E46A147C7A339
PeID
Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.e`&
.^f*
.:1Y
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.e`&
.^f*
.:1Y
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙