Suspect
PE Executable
MD5: cf45ceccffbbdc3f91aed61a3bfca6f1
Size: 5.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | cf45ceccffbbdc3f91aed61a3bfca6f1 |
| Sha1 | 36554c407b733b09fabd2c137d63448aa5b375fb |
| Sha256 | a5a65f7a602bf8569bf18345c0741e765e9b0c574f0371dd9b016ba28876c0cd |
| Sha384 | f32ee776aeed309c48aed437b5d62aa8283213bbc1e0e4d1e717f51c6c4a15feac05e3b7e32815c6bb0b8eb3bcc470c6 |
| Sha512 | b41ab13a1ab4033df1376b2600dfdcc0f105e07d5f7d705c691237067f6112071041de44ad035604e89656462f1658b236646bf2583e76f657fc906f7956b59d |
| SSDeep | 24576:jbLgBbLguEQhfdmMSirYbcMNgef0QeQjG/D8kI:jnsnUQqMSPbcBVQej/ |
| TLSH | 9736235A31AC90FCD11B6374A4B38E26D2B37C5A227D970F8B5487661D03790BF68B63 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential