Suspicious
Suspect

cf09050bc0fca7db56fa1b2fdfa04ec8

PE Executable
MD5: cf09050bc0fca7db56fa1b2fdfa04ec8
Size: 5.25 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cf09050bc0fca7db56fa1b2fdfa04ec8
Sha1 1fe52fc21ac253d0a9cb6ecd889483e2fbccaf12
Sha256 a6451ad4f82ed52fdb02fd705438fe1dfc0fcc3b27e4ff3943413fa1e4dcd13e
Sha384 7c68928aa982861f20eea0835f47df8f87a1d703377668f32257798c04fc075f291aaccc783422b87f30ae18220bdec5
Sha512 c9d990ceff5a7c793098fcaacb4379136a14aba3d10d853925eb06059004b26828e0d45b7bf8d3f5f6e7471a7e1ea2c225ad5cad06baaee42a270dabfdc193c3
SSDeep 98304:yNQH/UA5dwuQpMcgvtyv+2Kh/AUPUkZRxzXaQuBvcMAx7uTbRhi59:4e/UmwuZvthh/AUMEZuBEMAx7uv7W9
TLSH 4D3633EA68CB56B5C886C3B89302706DF13B7B5546207D4B73CE59489E76F28903A3C7
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.@:,
.:Fe
.cR>
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.@:,
.:Fe
.cR>
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙