Suspicious
Suspect

ab70b3c627f2fd25fdf2f64f789cef04

PE Executable
MD5: ab70b3c627f2fd25fdf2f64f789cef04
Size: 531.97 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ab70b3c627f2fd25fdf2f64f789cef04
Sha1 6c58f5aacad5022003a4e184c335388fad7ee232
Sha256 52b18aba32d7fd019be9d2a62544572e887ecb5d09dee693c488de31686f5237
Sha384 6346b369aea1db6e0a145bfe410b17d4e643e60caee4b7c3e62e89cb9408b2594a86f737e0a72f0253f2f5ebe12ee27f
Sha512 ec8922ac8e3dd309b2f28643678d6eb0c635b6232aa8086a10b2311b2a718b00e2160026c716571308844011da524a9f5ddf4123c5577d4abe917844f1da3102
SSDeep 12288:wokxOBo6bxj559brTGm0s6A6+nJXKdXSiooNxB:+OrbfbPCmn6WdKKoNx
TLSH 8FB45AA3A39227FCC1E6C3348016762CF6613F66562886D6415AF7214F37B886F7EB14
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.CRT
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.CRT
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙