Suspicious
Suspect

fb66a42ca526909d3e91517c52a10050

PE Executable
MD5: fb66a42ca526909d3e91517c52a10050
Size: 2.99 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fb66a42ca526909d3e91517c52a10050
Sha1 000842d23330d95dbb3dc2f72508225c86ad82ac
Sha256 b4d60147a359fe8b230d70da0f155e813bb517eb716ccd3baa70e68e4b63c7d1
Sha384 225ca2c0349baa5727458af234afe699774e4f20f33d45bd2fe03120ea24a119f0d9e34f6700f19c51eac5df4c1a8d17
Sha512 8eb70b6c6e0c05df157728d3edeee912560814ea7dcf8b008c2314484fb268729d876fc75f63e5510b59058c1d16b4cc0c616c421f005154a368d118e5837698
SSDeep 49152:8JXlVGKs1gmyPPYbpJ1J4G3gnQhRnTQbk8g3iFo2vCeCggPptKnFFp8dn1KH5jp+:85zQ1CAbpTvwnQTZ3v0uun/+d1K5jyjV
TLSH A2D52284FCAB4CB8F833C77313D3A47DB029BB494A618C8762D967506D526287D3A778
PeID
Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.JP
.,yn
.%Y9
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.JP
.,yn
.%Y9
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙