Suspicious
Suspect

d6dfa25d2c64147ab1188c4786ccbf94

PE Executable
MD5: d6dfa25d2c64147ab1188c4786ccbf94
Size: 3.59 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d6dfa25d2c64147ab1188c4786ccbf94
Sha1 f9546c643520688cc2717931c571e51b4cdb2260
Sha256 6cfb4609e950b151d76ec4b0b7330e5a9fe557e47739b2eda9e6f0dd071bd0fb
Sha384 ccad6ac2fadca64c238632a6462da27f0eaa696c72f67e26bff1fe617aacd3cc8be8afbe85188b072ba8e28b0fbcd715
Sha512 6bcbe7477446d754ca89462224f107c27d5bbeb1742b348d8409039bdddccd162fd133570d1197631dba8aeb773f828c231268390fc75808dcd652f11bcc5d80
SSDeep 98304:cFsoSEz4YhxoSdOvuFW4oFe4lc8++geksRJ8Jw:8UIOvuFW4D4lDTk88O
TLSH 78F53302D4239B6BF132B77FDDF57D8C157A995E0A2E9BEBBC235B060460CE4A391118
PeID
Microsoft Visual C++ v6.0 DLLUPX -> www.upx.sourceforge.netUPX 2.93 - 3.95 (LZMA) ASL sign UPX 3.02UPX v3.0UPX v3.0 (EXE_LZMA) -> Markus Oberhumer & Laszlo Molnar & John Reiser
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
UPX2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
UPX2
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙