Suspicious
Suspect

ff65daa3a1d882216bb86568397a3fc4

PE Executable
MD5: ff65daa3a1d882216bb86568397a3fc4
Size: 2.98 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ff65daa3a1d882216bb86568397a3fc4
Sha1 62c0de2f2338d7b783c7ca0997b6c47123f0b330
Sha256 4ce24ddf15280392b9f2c021d9b5467b3b034f4fcca2267d71dd5225667ac04f
Sha384 48a564bcb0de014823374e5cf7a1ab882f8f0f972271163d1b56eefd2e374c3f42df29f01d8ad9b6b0f038d2e06e222f
Sha512 dddd409069d647aed6355072bdf87d1920c263368587f510f5c0221b2101de3edc34cc4d17fe2bc61bbe5a988d86495eeec930a6c5db00fb7198b433db1c9994
SSDeep 49152:I45bCsZt5MScui0Z4EFAI8l5Q/NpgnUDXn1rhnsbavRo1s3E/M:IOCcTMScuFzFiQ4IrhnsqeyE
TLSH C7D523D9BCF605B8D833C7AA8E82E47DB22937854B654EAB3BCC76605D025446C3633D
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.V27
.Z]&
.Gwl
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.V27
.Z]&
.Gwl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙