Suspicious
Suspect

ba1a663e230ce317ae337b5d83046ee7

PE Executable
MD5: ba1a663e230ce317ae337b5d83046ee7
Size: 5.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ba1a663e230ce317ae337b5d83046ee7
Sha1 7900cfedd44cd639839f0c4f6d382e62fd541046
Sha256 b7b1cf77eccf7fab42d83f57facdb1105d51050295a044ecdf75cc8280679788
Sha384 dbcb4d3c11d21127a85aa7eaab4932af0ac67a3e5ccaac76cd50efe4e661981905adcd0c40da2ed14e5ad0ba421ec289
Sha512 6960616cedc118240f27bccf0ba2527439f661029af18825fb6475b5ca6e4c80cb402cde72b86ba0d02d2b3c587b5883ee584f0c64634e98dd6b5a246b6058cc
SSDeep 98304:6eEZUQ9DLUUK09ofcc9uFsX4luxO/39bAOnnYBsvUQeOyj:5AXRTMuqIu2FvUQe
TLSH D1363380BCC299B5D4A6C3FC595374BDF33ABBB28564BC1576ED28044DAEE24253E780
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.>O]
.S0r
.WNO
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.>O]
.S0r
.WNO
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙