Suspicious
Suspect

bf8ec2994ca75d5e09c66a0fc740459e

PE Executable
MD5: bf8ec2994ca75d5e09c66a0fc740459e
Size: 609.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bf8ec2994ca75d5e09c66a0fc740459e
Sha1 018356c22bf7997520cc341b97eb7e6e4b4ccb67
Sha256 ec0078d806fcb7b0ef538a51ae03217888ce1bd3e96a73beceecc2c12675d77d
Sha384 909884228df99b5cfc3ca855612d2235be41ea7d5e36f3cf2255fe90ca600249a72e4e8ace703724c10dc9cd614b4997
Sha512 2f631d8242cb1848c67934b17e74355f8450021283ffe30d48f693b12caa60601cb83ad2709d4ba01037dd32e30fd47fffc6f2dc730eae5c8a868a704f40d20e
SSDeep 12288:/IG1d2uVEQH25N1H+G3LlH2cMUrQNBVdr6rx/i6/E6q1EW0pJ7v/T:H2uVEQU5blWcMDBjWx/iHniW0rz/T
TLSH 51D4F206B7F624D8E1B3CDB88C514A62FBB6397347405F6F13908B796F23661AE19B10
PeID
Microsoft Visual C++ v6.0 DLL
[Authenticode]_6363df52.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
88
ID:0209
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x91E00 size 12152 bytes
[Authenticode]_6363df52.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
88
ID:0209
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙