Suspicious
Suspect

eaf6b05d4deba01180fea6ccac72d3bb

PE Executable
MD5: eaf6b05d4deba01180fea6ccac72d3bb
Size: 3.02 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 eaf6b05d4deba01180fea6ccac72d3bb
Sha1 2f1761e9c30ac995e9d6e15d0eecb39fc10722c1
Sha256 d91ff636d4b2260e16e231bf7946371b5bee421bc494373e236ff90eeefdf8de
Sha384 3fca3043c4c54f15b257a344fede2ad1aaa4e37918d9fe3bfe6018ab4be53f55612edaf332818c1065cfc55cca45277b
Sha512 a607c2752dcbc0e5d8dfeffff60029734ac59aeecf615e8a977cc62d3a86b0348130aa98f94c645fd13cc0dcf83d2200e49b76499d0542678a76889e94c6b8f0
SSDeep 49152:aJpTvv8sOMTEmY0zo1h6d5yQgp6mdiCWH8DaD+jgH5hPw3QhlagLJsU:aPTvhOtnTU5yQMrdiC28Da6j85hY3qZs
TLSH 97E523897DC23AB2E032C3774BA3B4BDB16D7B5986609C5E37CD6B109E129146D3B324
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.H"[
.s5i
.@F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.H"[
.s5i
.@F
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙