Suspect
PE Executable
MD5: f0d062c4f07188525d9b14c975e871ed
Size: 5.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | f0d062c4f07188525d9b14c975e871ed |
| Sha1 | 8616383a669c0d3ba743bc9f122954257fb28bd9 |
| Sha256 | e1ee2b7aeeb62f063134d78df6e522afde0952eca1701fb8d0835abe18ef16bc |
| Sha384 | 7affac796f1cd5cc2b8b5ea89b3c7de2175c0aa4c35a6d58accfdc3586aa828d73601d132d8ba1c34018b81377d20e69 |
| Sha512 | eb9241923f35e40013bbad96cf800f22e884872eedbaaf77090ccbfbf2550d1dfbf7fb823292c349422d9b31cbf64f4564a2382c852aaf1010fbe60ed87b7bd4 |
| SSDeep | 49152:jnsntqMSPbcBVQej/1INRx+TSqTFQo6SAAR:DMtqPoBhz1aRxcSUF36SAE |
| TLSH | 6536238A31B881FCD1072AB584B78E16F3B37C5E22F95B0F9B40457A1E13755BB60B52 |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft v12.00 64bit C++ DLL - sign ASL ( 64 bit ) UPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential