Suspicious
Suspect

eef744fd80a3520d1c67e6eb98f091bc

PE Executable
MD5: eef744fd80a3520d1c67e6eb98f091bc
Size: 3.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 eef744fd80a3520d1c67e6eb98f091bc
Sha1 548a5108fef4d712e6e8ca26223be5aade0bf89d
Sha256 6bcd0a97bb8c444b66e686e2bceb32cccf4090f13b6b5ed778c0341e31fe9d8a
Sha384 41f497f9d01cfb768d7a527cccb17f19ff3a0adf54ec06b2f9fc452fb3f6f8920b9e0318804dbcc300a8ac915e5ddd31
Sha512 4bb3d5600d09c80dd23b0607ad30e09f205283170c46c31401f3eea6efaa29a45364005d1b2cba501ff3174827a494931c641c08dfac5a100ff285504a87301f
SSDeep 49152:xAOZA9sAXMRPEGt60S+6lCUiGj40257NyyDhl5KrDZADcTZ:uOZAERdj6NgJheBHF
TLSH A6E52398BE9A7671E033C3F783A728FD711A37908B648D5E35896B106D13428BCBB355
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.n9h
.Kik
.JV5
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.n9h
.Kik
.JV5
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙