Suspicious
Suspect

b2155938ceca6a925f0a47c752a80520

PE Executable
MD5: b2155938ceca6a925f0a47c752a80520
Size: 442.88 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b2155938ceca6a925f0a47c752a80520
Sha1 d7b0e9544a65ef4edb76803fe01661d621501c26
Sha256 bd09ae02030fa7bc915268f0c6efd1099f56eb70bc2cbd42fc86571c6de2fbfe
Sha384 81687beb03728157a51f0969906f2addc42e08739329ecae2696245254a9fd224963808895842e8c4a03daa716b0cd2d
Sha512 9bc61b600544ace00511d284f56e6dcf83f9b4223bfb3ece0162cfb58d31fdccd96a3188b471ee736d8b21b6d740e8e0e26f67b192a89e9046553b12719a1d39
SSDeep 1536:+8kMx6+Jjnt2jz4KU+64+OSn2zTlobK3r3fAJr76vfyL90c:IMcq2H64EMT24Tfgkg93
TLSH 18941193BB8D1332D90201B6E28EC3E68BAED5DC3277252554FCC51C22159E983BB7E5
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ v6.0 DLLfasm ->Tomasz Grysztar
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_STRING
ID:003F
ID:1033
ID:0040
ID:1033
ID:0045
ID:1033
ID:0046
ID:1033
RT_RCDATA
ID:07D0
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_STRING
ID:003F
ID:1033
ID:0040
ID:1033
ID:0045
ID:1033
ID:0046
ID:1033
RT_RCDATA
ID:07D0
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙