Suspicious
Suspect

b6c54f210cd5cc94a9e99fe406083bc6

PE Executable
MD5: b6c54f210cd5cc94a9e99fe406083bc6
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b6c54f210cd5cc94a9e99fe406083bc6
Sha1 250af1836793ba6da8dde0f2f9332a54ef9109ca
Sha256 bb47bc91de6fbf45dd8d3348cb6e26fcf1ef2830cd326ec2eaf0e2ff15564ca7
Sha384 f8328006b10af63fbb0516e5310ee8295720e22bc01a8b46819e4dc01382b9b24a93b6bc3f033e3812e3b5142f0a0503
Sha512 5444043a0897a9f5b4a37d4b31ef525320a2871ef85cee8202ba762a46e54418aec6c2aed220172503c7bd89739a536819ebf6106d0badf8cc98cfb3f61c47ba
SSDeep 12288:jbLgmvbLgPlu+QhMbaIMu7L5NVErCA4z2g6rTcbckPU82900Ve7zw+K+D:jbLgWbLgddQhfdmMSirYbcMNgef0
TLSH E6361259336C81BCC11B523494B34D26E7B3BC5A127D970F8BA48B6A0E13790BB78B57
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
b6c54f210cd5cc94a9e99fe406083bc6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙