Suspicious
Suspect

dfe503a105bacb0430a18b7e92bd7768

PE Executable
MD5: dfe503a105bacb0430a18b7e92bd7768
Size: 2.95 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dfe503a105bacb0430a18b7e92bd7768
Sha1 22c575a963bc49cb27066570eee17b439d93a4f5
Sha256 ad9dd438fd00d4130d2e993d0765d2095c71aa68f156e2e7b53863f0e18446ee
Sha384 622c7c4a73746e011d09b8f80d45974e06a296b10a2a2942773c8f152eb6ebbb1067188da135d8e09dd9e4b23ddec4cd
Sha512 c6406eb233d3cf26778953a2a6e508619c1af6b9f3b610d0e61c36c4a0b4c54649a84f526a4172e409e8d3b1b42979d0cd342a375298c367285435ec84963c15
SSDeep 49152:gYVh9yXAI16BCJM0kG9BtO3Whm8R+uisKKCMqGCjx3u805yhVSuJkJ:nVns4B90kG9BCWhpR+pncqGCjVo5yhkq
TLSH 6ED522E931F22AB4D877CBB18FD6F87EB16E3B844B744E5276C865005E621586C32372
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.|hc
..pM
.}6I
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.|hc
..pM
.}6I
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙