Suspicious
Suspect

c9ec45290a8a75c40b4ddce93bd3011f

Share on LinkedIn
Print
PE Executable
MD5: c9ec45290a8a75c40b4ddce93bd3011f
Size: 4.39 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c9ec45290a8a75c40b4ddce93bd3011f
Sha1 4d146e5c048f47c537336fad5baf03ad2e1c3f7b
Sha256 cdf73be2cb641278135f50923637423362c8cc0a85609dc7ffebc44dbb2e4e72
Sha384 d4f4cc694d000d4e3b3522312316ae9263610ac6b243ec99a04223c738fff2c1c6661d6a5c0ab6b46c6f1379c4152f21
Sha512 98caff570b85b97dc8b7644139d6aff74af813532cefbfde6472505b80b3302312eb30f35f745d432df4dc1ccc584d45f00a5d99228553bbea9068777152dd54
SSDeep 98304:20kwvTTig9D5LRnrWNa5OhRYLR9CbUaJaS3be0jone76:F7b9D5LRCNulwDbeWoe76
TLSH AA1633CF55FA9E4ED069013764669FADDF0D894B40AD0BCD3241EF998787B0B8253E28
PeID
RPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙