Suspect
PE Executable
MD5: dfb3cccf389b73c970f4c3a9e4eb0937
Size: 5.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | dfb3cccf389b73c970f4c3a9e4eb0937 |
| Sha1 | 6752939901ff10fa9057c20c1926a417484d1608 |
| Sha256 | 43473c2ee7dc5543f3ce568a80b3cc372e8b395206e73b6da222bbe15569faf3 |
| Sha384 | 1af116a6c62fea35e6df39fe9ee1341c0e006664b227974b70cca335503b43a54f9f7931e14e2e7c88ba652ad7b5ef86 |
| Sha512 | 2fa8f5fc1effca401f5825f2a064b1fa78842e4fa512a0a7ecedc308192e3b74b4e0ceffaa60bb62a6aae2cafb467433c617ad6102601f3daeb8acc1b87766eb |
| SSDeep | 49152:jnznsEMSPbcBVQej/NAARdhnvoAHB3rtgiomvJi:DTfPoBhzNAEdhvpHBxjNi |
| TLSH | 3E36334971A850FCD146077C94B7CF55B3B7BC9926BA4B0FAF848A261C63780BF98712 |
PeID
Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential