Suspicious
Suspect

9a2ab99004876abd33ee019280487079

PE Executable
MD5: 9a2ab99004876abd33ee019280487079
Size: 2.93 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9a2ab99004876abd33ee019280487079
Sha1 143954c1c063d8c33dbd8d4e6805f61bb04d9fcf
Sha256 686492d6fdc77d25ac4965be3fcc2cf0bb51bfdb41cc52f500aa45f542fe6660
Sha384 c0b2fe03243b9ccc7026218897390aeb584f4cca69bf1290fcf522ef27da086f685e8cb9c3e34a18b990d67d9729955e
Sha512 dcf931a9f2d3b82b2f9daf243218f39c80e4007a52f9d4e216a84e4debb4a824912c6bfcc36cc7ffec61c7d29db515947d83db475fe2cdf7c228454730a889c3
SSDeep 49152:DznVb6S7gHmckYaZdmU6QyXbwtiByYljbaz4Vnt90Yi5yHP6X3CqlhzNkwQgUNRW:HnV2S7gGckfqhPbwtkywazqVHU/lhRkm
TLSH 17D5238638F12AB4C47BC7B29F43E92EB06A77454AB48E1BBACC69014E531487D37375
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.o(*
.vwP
.kxd
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.o(*
.vwP
.kxd
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙