Suspicious
Suspect

babdba08319057c12f2042822da13243

PE Executable
MD5: babdba08319057c12f2042822da13243
Size: 2.99 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 babdba08319057c12f2042822da13243
Sha1 9da026ee3620317e28187109fd30d396bee54eb6
Sha256 72f18eaec039b55d65fba9c8211dadf205ec2d2ea48c181b51cfc6fdf5a0a488
Sha384 c65a0d6b07834249b279689b58ff25f1a793fe216f8fc654a092b50d890951073070cd23cc2bd6e345f7b30e6aabeb51
Sha512 f8d6bb685ce9aca02bbaf4c018385e1b064a09b131d97787cf830c3b644eec1fa880875c88bf978521af5a44a51e763b33fbb3073a6a31a1e2cadcae33d9780e
SSDeep 49152:HUaWXksiONPZZubSiMO6hortoa3RcUVOnWDO9d5/gfqKeLpa4rgvuH5YVNjXOVnK:HUdUsfueiMONJf3Rc3n1X1KeLpaG2W54
TLSH 17D52389FDE60931D472C7B746E3746EB13A7B84C6A08D5B76CC2B00AE029196C77379
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.[7>
.<%K
.e#6
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.[7>
.<%K
.e#6
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙