Suspect
PE Executable
MD5: e5378257ea49f5fdb1a312847315d7fd
Size: 5.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | e5378257ea49f5fdb1a312847315d7fd |
| Sha1 | 93607149c5d62866a95f52d63f5c5648c1406f97 |
| Sha256 | 908b894dda4cf38ee4bd4ede8d07ce880e71d3e9dd4c401084f5f8d9fb675fb6 |
| Sha384 | e6487b3142376204151cb1e098aada87e58b58b97fd64c817b8a5d3f55b4cea72ab28c63b411e3c26dbf12c95a3c3d67 |
| Sha512 | 12ca170b71511c72d83a7cbef152b8a7e0ffafd792a6580f29008f1500ba4efc14d309098d95918b935efa8e59c835fedcd1a0f8ba62112a2e82fc9ae0113cfb |
| SSDeep | 98304:DXDqPoBhz1aRxcSUDk36SAEdhvxWa9P5J3R8yAVp2H:DXDqPe1Cxcxk3ZAEUad7R8yc4H |
| TLSH | 513633547268D1BCE0050A784CA3C99AB6B37C55AF7A4A0F7BC0B36F0D73B56AB90701 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential