Suspicious
Suspect

d796641f1c891e4dc465f1b9cd8ec689

PE Executable
MD5: d796641f1c891e4dc465f1b9cd8ec689
Size: 3.89 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d796641f1c891e4dc465f1b9cd8ec689
Sha1 b4f1c2dfdac3e70248d56e6fb72a373dc01e15ca
Sha256 fa26fc81be65cf838b8619888564eab5888e017c017f29308852570f61aa028d
Sha384 3ede62078f51368ade6c81b7c6696d75572989a9d2b18caa136ba1a8061b5019e122f2f1fe95c36a2ce158877ac2e183
Sha512 ea6370ee746aad45fcd37ae9a211fa624e87a9046dd755960b1ebd13ea3a5cea9b6c5eb09a88a34c36c1cce2af63a4ebc162ff457921bca5861ceabb51fab9a5
SSDeep 49152:YE08QzxLC8C0TbsRpdSh6P1tWyett9DH6+b6EWuaSVJXfRBFtX549iyIeYIU6ii:Y1887TbfEwK+USdBFQXn+
TLSH B9068D03E69581F9D0AEC078C35B9637EB72B88A1630B6EB17D45B612F23F906B1D315
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙