Suspicious
Suspect

b563a94c360514149e7bb61631f0f3c9

PE Executable
MD5: b563a94c360514149e7bb61631f0f3c9
Size: 2.91 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b563a94c360514149e7bb61631f0f3c9
Sha1 62fd49ce6250001ad1110ccc44ee90a06c97c168
Sha256 e17367bb85b6098661042e2cd49cdf4822b92a9765c6d175f5706f8b8adde9c4
Sha384 2a050a4597fbf2cbee74460668edbfb28a0682828ad173a9dba38ce19eb54f325fc4e1dea7f3dfe357637e297ffac4a3
Sha512 a30ab755201cc6f7c5c2a97eb5ca0eeb4d7c131c644fe6de0af26dd7b13eccd89f29436f84d5785f3528aea98627aab3ab2b49f300a7daae8457c0bc22373ac8
SSDeep 49152:YRKSHDCqj4MefoyGDdjPKWI3dqfSCMP7urjQDkWV3gSpS8AuaipSMewQBNGwK2hF:omqjofojUS/jYfR9JAZip5r1Fw8Ook
TLSH E1D5236AB5F91978C477C7B28F53F56CB02C3B4C47B00E07BB992A248D6358898367B5
PeID
FSG v1.10 (Eng) -> dulek/xt -> (Microsoft Visual C# / Basic .NET)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.::m
.t(a
.UuN
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.::m
.t(a
.UuN
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙