Suspicious
Suspect

ab85fd8e14032d3f07865e7da41191ae

PE Executable
MD5: ab85fd8e14032d3f07865e7da41191ae
Size: 5.29 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ab85fd8e14032d3f07865e7da41191ae
Sha1 e9e85b7ad49171ae07ced4a298be3ccd7c0efbac
Sha256 1e5be4fab2e11a5a450d10e056be635d6695e10ba02933db46f49d2631c7d910
Sha384 e387a332fe273ed7597246dce36feb9641b311e6c8534af9a133df76d1ed515bd1f5530c1c9102061263820b9bb24208
Sha512 b6f460e158368c9828d2fb966a5eae02fe9525d027f1d72d19b4ac2a10e55fb1f612d595ed2aaa5134bee9c950f1bc691b3a1bb9d750a38b2335355c654426d4
SSDeep 98304:lWkAJqI6fuRvQsmJMpBVWm+U95fTakCl7DBUnu04aGyL0UjCJbikq:lWVaWRvt1pBVWqrro7tZOgUjYbiF
TLSH F73633747CCAC978E042C3B85A02607EF27E379285893C5676CE77409D9FE29A43D786
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.t+9
.<@l
.Klw
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.t+9
.<@l
.Klw
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙