Suspicious
Suspect

a252016bf277874e274a93c2403bae03

PE Executable
MD5: a252016bf277874e274a93c2403bae03
Size: 2.96 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a252016bf277874e274a93c2403bae03
Sha1 00f2579a8c3f286baec64bc3f8abb4bb6451283c
Sha256 cd4d9ce29b22ccd9bc97d50d32923b84b44a2ce081b13124cda0a33523f86763
Sha384 edf72916a41735835761ccdc22d741828c1b5c124363db856675cb99232961ae4b88537e33614939bc8ce4d109ef641f
Sha512 c636aa33c80240a42b7f23e88ee0bca7f8e4f0465aa0a76885cb6d05452eda98293488bfe3b3ca252502015bda1585b0820a3535a031438d86cacc5c9034535c
SSDeep 49152:Nrd0Oax0A7OBhbZakbArDneNcjHBVwnbZGkBQlF90NZ/jIMWd7fhCdkz:NrqOaOA7OBVVmDe9tmLi+MA1Zz
TLSH C7D5235AB8F649B5C435C7B28FD2F06EB06A77958A254EA3F2CC9E00CD579581C39B30
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.=%P
.;~^
.@gJ
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.=%P
.;~^
.@gJ
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙