Suspicious
Suspect

c9ec45290a8a75c40b4ddce93bd3011f

PE Executable
MD5: c9ec45290a8a75c40b4ddce93bd3011f
Size: 4.39 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c9ec45290a8a75c40b4ddce93bd3011f
Sha1 4d146e5c048f47c537336fad5baf03ad2e1c3f7b
Sha256 cdf73be2cb641278135f50923637423362c8cc0a85609dc7ffebc44dbb2e4e72
Sha384 d4f4cc694d000d4e3b3522312316ae9263610ac6b243ec99a04223c738fff2c1c6661d6a5c0ab6b46c6f1379c4152f21
Sha512 98caff570b85b97dc8b7644139d6aff74af813532cefbfde6472505b80b3302312eb30f35f745d432df4dc1ccc584d45f00a5d99228553bbea9068777152dd54
SSDeep 98304:20kwvTTig9D5LRnrWNa5OhRYLR9CbUaJaS3be0jone76:F7b9D5LRCNulwDbeWoe76
TLSH AA1633CF55FA9E4ED069013764669FADDF0D894B40AD0BCD3241EF998787B0B8253E28
PeID
RPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙