Suspect
PE Executable
MD5: f810b91290793c84b4e5983df317342d
Size: 6.8 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | f810b91290793c84b4e5983df317342d |
| Sha1 | cfe8f4f38221e1759c168027e2a562d6b05bcd8b |
| Sha256 | 5ee4901b73444dc6c29e46d0b3f15b0bcd3e8e18ba67eac8b37a75d00f2efa35 |
| Sha384 | 0a733373873ff0a4b2aa8e326de8c14e0afd193e94692f9735b2e47f705d5086a6779f0c76ad089df82af42283bd1e95 |
| Sha512 | a6b3d96cd373661cbba4088a4ec27bd89fb01d55ee37a316dfbe53491f3636ae8451e85853048d6abcf4b1f4a7d9648be92d6a0cb18381397019943b9b0bf1c1 |
| SSDeep | 98304:GIGhLFuKll/BJwl970i2gqxIeP6dsU+I/BUDJ:gVFuCl/G97TgdP6n+I/B6 |
| TLSH | 83666CEA24C2679DC416C57A8353FD7F984F71764B2BA8E3A054B2229D27CC03A75F09 |
PeID
Microsoft Visual C++ v6.0 DLLRPolyCryptor V1.4.2 -> VaskaUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:exe
Shape
pe:exe>pe:exe
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
| Info | Overlay extracted: Overlay_bdad3719.bin (4338176 bytes) |
| Info | Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_f62a3583.exe |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential