Suspicious
Suspect

e1ffc20bdad432f1be7f63afc6058fc0

PE Executable
MD5: e1ffc20bdad432f1be7f63afc6058fc0
Size: 15.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e1ffc20bdad432f1be7f63afc6058fc0
Sha1 ab73676e1f5593429b6b9e172f6b73aa508a50fd
Sha256 882f1cc8f727b6077eb0e37a3014c2e2750f595cffcb22b36f61bdcc5cb7699d
Sha384 32cd063eca2707098e8ad4b814eb8d0010761211d01773b06dac2433f5c2b8298d36167382c3c3e5ff452fdc7ab181a8
Sha512 d4aaa878a0222e54e6e50c7847b41fa560c03bb76ad6bbdd926ddfd3d9a382ee545970f9ca6e9fce941c7b6381c81d3cd9b37099486c3a586b6472c132e2268e
SSDeep 192:fqHOoLPoHeVQBNBY0fidcj3wJLsN3AAK8BzvTt1NpkAm1paLsehDPP0B46UFXqAe:fKOe2/7c9sN3zfZR1m+RGiXJ6C
TLSH D762C7D6EDA32F6CCE4E80703A51F878B97476908A65D9E3D7828C306D639D00534EFA
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙