Suspicious
Suspect

e6dca6bbb610070f9801a6bd10245601

PE Executable
MD5: e6dca6bbb610070f9801a6bd10245601
Size: 5.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e6dca6bbb610070f9801a6bd10245601
Sha1 8965f590a1fff9a04936b63fb302db76078c237b
Sha256 23679cc38b8e793d6205e5d75713a931646b4e5e698d1fd258524ec7a305c34b
Sha384 38f3dc3958683aca65d4fcc45e849851e32e0caed880cca5ecfc37698edd312a0f836d82490daac34dfbdc0b86650a30
Sha512 87f5446c268fc9aca53cc0238b3d10514dc7af7ec1148bc644dbde9cfd48f7fee4679ad46c6bf01b19fb1650b434b933082caffe25115f9c0e239752c7588454
SSDeep 49152:jnsnxQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnv:DM6qPoBhz1aRxcSUDk36SAEdhv
TLSH 7136235932BC81BCD106167844F78E27E3B37C5A16FE5B0F8B408A6A1E13B55EB64B43
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll
Shape pe:dll
1 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
e6dca6bbb610070f9801a6bd10245601
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙