Suspicious
Suspect

dfb3cccf389b73c970f4c3a9e4eb0937

PE Executable
MD5: dfb3cccf389b73c970f4c3a9e4eb0937
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dfb3cccf389b73c970f4c3a9e4eb0937
Sha1 6752939901ff10fa9057c20c1926a417484d1608
Sha256 43473c2ee7dc5543f3ce568a80b3cc372e8b395206e73b6da222bbe15569faf3
Sha384 1af116a6c62fea35e6df39fe9ee1341c0e006664b227974b70cca335503b43a54f9f7931e14e2e7c88ba652ad7b5ef86
Sha512 2fa8f5fc1effca401f5825f2a064b1fa78842e4fa512a0a7ecedc308192e3b74b4e0ceffaa60bb62a6aae2cafb467433c617ad6102601f3daeb8acc1b87766eb
SSDeep 49152:jnznsEMSPbcBVQej/NAARdhnvoAHB3rtgiomvJi:DTfPoBhzNAEdhvpHBxjNi
TLSH 3E36334971A850FCD146077C94B7CF55B3B7BC9926BA4B0FAF848A261C63780BF98712
PeID
Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
dfb3cccf389b73c970f4c3a9e4eb0937
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙