Suspect
PE Executable
MD5: fe04a8e07af1dbc71f42f5426f8ea8f2
Size: 16.88 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | fe04a8e07af1dbc71f42f5426f8ea8f2 |
| Sha1 | 30a88e1ba76824e2ce56e8bbdc771e87f7b0a791 |
| Sha256 | aa5045411ba7da09339ea56b718435ed4db6970b77a2495750427c3e0983f4b5 |
| Sha384 | 9580fbb1c1f5882e21d7b37793315ae2159002b1475fb119cacbb4a9876a6b8ed617c4016215653a294df8d5442b22d5 |
| Sha512 | 96ab705771f0e165957bbf321db6480ce8ac3d1c8fd02f29989357ca3306a67d32089f9a62b1494db426b97ed5db5652619d0d25fba9333786fbac10f220c7ca |
| SSDeep | 393216:+pbs7d4Hda49iujQ/sqA/3GwsdCWIqpkEsc+1aId9rrl+vNLm/jP:e84HdJ9xjxnBitmEsxYIPrl6CLP |
| TLSH | 390733053F62A8F6D2AA80369E0EE3555835E2AA52C8CF17A3FC5E4E1ED3D7543430D9 |
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 8
STICH kept: 1secondary ignored: 7
bin
6img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>arc:7zsfx
Shape
pe:exe>arc:7zsfx
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_09f72026.bin (16690164 bytes) |