Suspicious
Suspect

a1f56ff4b27393749917e804333cd16b

PE Executable
MD5: a1f56ff4b27393749917e804333cd16b
Size: 3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a1f56ff4b27393749917e804333cd16b
Sha1 7da8d200522be7a47b16b98085d25f015d8e3ea4
Sha256 6db1f0f5254c8fbd69ecf83c2d99b825931b252c910e031e657907ce0c8d8f3e
Sha384 38a237bff2033ac006052aa23f99202b7221344fdfa89a5bf8dc2d36b239f25a27483c7aa0dc357869ea1ff542e5dba0
Sha512 badda7cc2a2d30b537898eb90a2393b036dfcc112eab1d418cf0920bc704104d378bd621827b313aceed516c14d654df688daebc2ae447b9d471f893f441e4a1
SSDeep 49152:fngHVcLWW9/5qrQAFldt5H16HmYOSR+dXlgNtumOG4VQl24rV6fCF:fng1cLW2hqrQoVOm8+dXxmh4s1rt
TLSH E1D5238ABDF60974E436C77A9CD3E06DB1297B5182244D57BBCC1F008E23A986C36779
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.GfW
.SS=
.,e{
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.GfW
.SS=
.,e{
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙