Suspicious
Suspect

f40f549eff44146673fbb3324f013c87

PE Executable
MD5: f40f549eff44146673fbb3324f013c87
Size: 2.97 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f40f549eff44146673fbb3324f013c87
Sha1 9d87dc2db7b47f50d8dac0436410a84d55313f27
Sha256 cb65f0e3cc600d43b6961e8f51d01c1286500fbaa76b1f6aaa576a36ae7567f2
Sha384 88a1b98f60db06680264480b974b7d82897b24c6f861d9108c88868715da5b46fa5e87ca21b88e52328ce30e5413d522
Sha512 e14c3f9c607836a310d396fef9c67e682da444f8751816dfe8a8cf60c5636909e427a4b9261fc56ce01d8e2040161018ad0af5ed018a7c236a72ad773ae711a6
SSDeep 49152:jki9aNi/xJuayg/S7BOjOZKbPolFclPujFNSbnobqLD0UjxZOYh/VyCw+ZVZ+xXc:jF9Gi5lyesB+DbDoILD04LOSdyCFZ3i
TLSH B7D523897CB60875D433C3B29F92F46E702A3B454B318D9BBBCD2A009D22A655C37779
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.K9M
.Qhh
.=Y`
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.K9M
.Qhh
.=Y`
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙