Suspicious
Suspect

cff3a9e9ad28ef4ed30af09ad3d55586

PE Executable
MD5: cff3a9e9ad28ef4ed30af09ad3d55586
Size: 2.95 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cff3a9e9ad28ef4ed30af09ad3d55586
Sha1 a97365e84cc6c593aac2edf58dad704936177b38
Sha256 4cef725a2fd962110be3b7ad4e01518a78d3bec24e7d078a5fbe1b35f38d9d2a
Sha384 87dd6bb6caea9e2bc8a7285aaea65ed980c3db114f27c8d81d1837ae06cefea475e543d74d886b5e8f8b09446c3d4ea5
Sha512 8a81d2749eec807b1de67802a1d3a5b90c0d350d00ab6ff0bd5e3aeef83cf4fd7d7fa2f34e698d9cc17b8c62137ae627df536160a39f95e59d4782782c6957f3
SSDeep 49152:0VAQsnJFqw4RJiLf6MoeOBM6mC72zLIFg0n7SLKRwvxsjvX5ygafusWE:4sJFq94MP3mWg07SLKRwv8RyhfFWE
TLSH 5AD523CBB8B20938C47BC3B68F92F07EB01A77458B2A9D97769E6D408E134546C36771
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.,
T
.
`9
.SSv
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.,
T
.
`9
.SSv
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙