Suspicious
Suspect

eec176c797a642834c4c5471f6ed19e5

PE Executable
MD5: eec176c797a642834c4c5471f6ed19e5
Size: 341.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 eec176c797a642834c4c5471f6ed19e5
Sha1 03dff37f5d8fe0144ff7ff8b581966fce5f16550
Sha256 73b3a8a8df3bc11ebfd7195028e2946a06f276a59e85c1e00ec1e28eec219f47
Sha384 2cff0e5371dba05f3433cc33415583ffd056bfbc6fef28b3da5eb5d4049175cdc4fee989d523429cbf80254b1e7f54c4
Sha512 9c88f01218ab3ed2114745f48e93344a524b1cb9a38c47107e6e0f5c67db80d8d630c4e545fb8a54b2bfe88e4f60c0ecf9780cbcc795700a5b40f2d8e9aeaafe
SSDeep 6144:VWbLT1Dg5NSQthy7b9FVdgCxS8mi7X54+W3qZoshdUZf:CPpgzSQtqFVdgCw8tZmqZoCd
TLSH 0B74AF25FB9064FDE167C038C2514A66E7327C890B229AFF336442392F26AE15F3DB55
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: drvhelper.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙