Suspicious
Suspect

fab8a4a9f469223a0fe384e135ef6e55

PE Executable
MD5: fab8a4a9f469223a0fe384e135ef6e55
Size: 17.23 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fab8a4a9f469223a0fe384e135ef6e55
Sha1 b3c73934d7fbe1b4b44d8e56aee7c20ef3ae4768
Sha256 6e774dc769bcf252fdba22a45fe3f55b701e8d53fa61525a26c255b10cfa2aa9
Sha384 91edae2ef741bd6b31fb9d2b8f194f434cba775bfadc9d86165ce7d116676a32104d696413dd7659171a5a2490b7de6e
Sha512 5bca974b7b5087aa0ca81674b89731ce661c5ca29764138e03cf4bc8aa3c10bf215a16050b47b3cf30103ac6202eb9ed525eda2a3da8eca80efcdde46457f0a1
SSDeep 196608:MrZcxYPT0nquIsATZ5/e8GVQqvUsdTSL5/JCq12Zv6njfvH4ZAyPt:7xYwnquPATfRGeqvbdTSLXhYAyl
TLSH DE07D08DD1F4B1BCC97DD03C4C040C16C37978666B22476A2996CED979B31B92BFAB24
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0065
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0065
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙