Suspicious
Suspect

ab29bfab5c4bfb8fcf88883a73019338

PE Executable
MD5: ab29bfab5c4bfb8fcf88883a73019338
Size: 4.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ab29bfab5c4bfb8fcf88883a73019338
Sha1 2bafa3018664bc3ef1546d8a49aa9443bdbcbe7b
Sha256 5cbb1d7ab165e888e31ed595357a20fd7119f3c70afe066fabafced1b1b28ea0
Sha384 43863710e42c27012b24b4580071fa2a47ecae61ea37b450e802d491b758797a412848c7459d6f1b1aab94f1832e5015
Sha512 acc25e123d15fa45af3fd80b221ecd932ae331f272104f37f438d270c4e0b343c7d39659114baaa934488d48e1a8b0e09fb102d4987fd202420c45bba0f8b742
SSDeep 98304:HcBkidFJKhMeXNpUhG7Ice/Wah2AYBxoB7P/OnvsK:HOP61XDq3Zh2AYABK
TLSH C51633BB50762F8FF181A7F2584052F96F86B911AECF2099C72CF4AD176A4B107DD904
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙