Suspicious
Suspect

b61499aed9660923cde55a2cd3c88cc5

PE Executable
MD5: b61499aed9660923cde55a2cd3c88cc5
Size: 169.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b61499aed9660923cde55a2cd3c88cc5
Sha1 8b1260a28e06c9c0c2d5ae48195aab24926901d3
Sha256 fcbe9f2d0f07f6c40b258228148fb61e94f4dc59962f2fd4e3ed3051d90cfa3b
Sha384 4e919a9ef6b252fe0f51ab7441f3592f7997f4c27c5c9297c6a51da5eaf19f8457ebf932a3cca4b6cc7e0293f86b6f9f
Sha512 ee96b28539d8a6f75a0e3678420f8e764f26ec36a91c07e1b66421bbd2d723ed818a3ed7dd756a0d70aaac8a1c73960f67f1888ca9cfd99750a465af1ba8461d
SSDeep 3072:btJ2fCsQiuzYJ8WreWgxgjIFafthDCMfCvOvHXrbl5STd:bwCszCYJ8OcgsaftB
TLSH FDF37D4A73E510FDE1778139C9551A05F372782207209BAF07A047BA9F272E1AD3EFA1
PeID
HQR data fileMicrosoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙