Suspicious
Suspect

c987878904b7808a850a8f300b9656e8

PE Executable
MD5: c987878904b7808a850a8f300b9656e8
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c987878904b7808a850a8f300b9656e8
Sha1 eb0efb4d11885c7897e2cdd7738c645789fab387
Sha256 e1f4692aef0eb5bfc8b0dd24d6b6df4bcb687429f41047b57b816b116bd29c90
Sha384 ab11638a4b21c1913d74fa650e6fe1be8f24ffe16bf7089a453afbd1ba0a336966fde7371831c9e6935cde40a6e072d2
Sha512 a4438de8da73106ff8dcb9558bf60c486afcf93e077558f92deab4ca7180333de60cd5a0755c3733498fa28378bb72499baa20a75cb9498eec054538dc32bd26
SSDeep 12288:jbLgGXbLgPlu+QhMbaIMu7L5NVErCA4z2g6rTcbckPU82900Ve7zw+K+D:jbLgSbLgddQhfdmMSirYbcMNgef0
TLSH 03361219326C81BCC11B523494B34D36E7B3BC5A127D970F8B988B6A1E13790BB78B57
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
c987878904b7808a850a8f300b9656e8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙