Suspicious
Suspect

e8c590a1a079434720c9960af3683265

PE Executable
MD5: e8c590a1a079434720c9960af3683265
Size: 4.2 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e8c590a1a079434720c9960af3683265
Sha1 489917a8f0fa00a82af62604d170e5e7d6dbd2a3
Sha256 11d5ae7c90cb88ff232dc6556ad9ed2185d981f23206defbce7eb88c19c0e090
Sha384 636838cf949ae43a2000804ab87d942e8cb6003df132589861908e2e0be388e45bee2f05ccf9e78a0f7cba46b2f40a05
Sha512 f919b749a8d3644b2886c125ad9c3856fb670663bffc663ca93cdce8ddf206545e99c1b47e291de1803cb5c1ab75ad17726c733065fdee2610db8b0b44969b75
SSDeep 98304:lnwePgEp/tDc8LZKcLU6Tt69fLK9mZapJ2:lpp/lc8o/P9fLKC
TLSH 8B16330C8A5C3AD9D9D32EFA16B21C79CB044B4046FBA295C825F5F1F05F7A6B711A0E
PeID
RPolyCryptor V1.4.2 -> Vaskax64 Themida / Winlicense v3.0.x.0 PACKED sign ASL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.idata
.themida
.boot
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙