Suspicious
Suspect

f810b91290793c84b4e5983df317342d

PE Executable
MD5: f810b91290793c84b4e5983df317342d
Size: 6.8 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f810b91290793c84b4e5983df317342d
Sha1 cfe8f4f38221e1759c168027e2a562d6b05bcd8b
Sha256 5ee4901b73444dc6c29e46d0b3f15b0bcd3e8e18ba67eac8b37a75d00f2efa35
Sha384 0a733373873ff0a4b2aa8e326de8c14e0afd193e94692f9735b2e47f705d5086a6779f0c76ad089df82af42283bd1e95
Sha512 a6b3d96cd373661cbba4088a4ec27bd89fb01d55ee37a316dfbe53491f3636ae8451e85853048d6abcf4b1f4a7d9648be92d6a0cb18381397019943b9b0bf1c1
SSDeep 98304:GIGhLFuKll/BJwl970i2gqxIeP6dsU+I/BUDJ:gVFuCl/G97TgdP6n+I/B6
TLSH 83666CEA24C2679DC416C57A8353FD7F984F71764B2BA8E3A054B2229D27CC03A75F09
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> VaskaUPolyX 0.3 -> delikon
Overlay_bdad3719.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
xfyfrflz
gimohcoh
.taggant
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
xfyfrflz
gimohcoh
.taggant
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:exe
Shape pe:exe>pe:exe
2 nodes
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
Info
Overlay extracted: Overlay_bdad3719.bin (4338176 bytes)
Info
Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_f62a3583.exe
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Overlay_bdad3719.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
xfyfrflz
gimohcoh
.taggant
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.rsrc
.idata
xfyfrflz
gimohcoh
.taggant
Resources
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
f810b91290793c84b4e5983df317342d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙