Suspicious
Suspect

c6dfd167fd82dd80565db7666771b533

PE Executable
MD5: c6dfd167fd82dd80565db7666771b533
Size: 5.22 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c6dfd167fd82dd80565db7666771b533
Sha1 95ea2a2fa74aed1c3c212c86b4de1cea1ddb7f63
Sha256 515d1d1c557be6bf4445f58f89cd638cd4bd21953f952257db4bc80b595fdcb5
Sha384 ab8119b2bf0855fd60a09f854fad054167d526fd41d80bf8693e3431ca3d2d00335798a7cbd19735c6305630de743fe2
Sha512 b3e5d4e0e39821fd30ac81b4f5a22ab81cd469e977ea5a6dc17fca4fdf272b7c464237f5caf0920c8be72a7193b17b78eea372025f99552f640b8a168f3a2b85
SSDeep 98304:GncDZI47fpSKr92bmxes6jO8ZVz6iuay5IE5Bxg3RX47AdMM:GncDm4T5rJesk5biOE5BaBJdM
TLSH 9A363385ADC790B0F047DB71425BB0ADF17A33A08AD6BD52B7CC77184D6BA15203EB86
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.K8C
.6t"
.ZpR
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.K8C
.6t"
.ZpR
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙