Suspicious
Suspect

ff80e537bd90476469004c6ecfda0675

PE Executable
MD5: ff80e537bd90476469004c6ecfda0675
Size: 2.92 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ff80e537bd90476469004c6ecfda0675
Sha1 3156fe31d2ba87370f0ffdbeeb23e1a5b4a7b0f5
Sha256 0bb09dc7ddb47aa43aa1a0e3bbf866e369a01b193514d6b4286e1143c5cd4f98
Sha384 2c6ada374e9543b7ee79a4c2dbd2f659d577d7457f71ff41efb0a2bd866318dfacaa9c3d4e3578d200e649fc8c93edf3
Sha512 a6b152f60b42e63e9c308e552f51ad13361f33f09bb6ff42d8b09f97d1455e8d47a9566a56c52a01d82e1335c69b35da4916b08caa2fe10722cb6a8477a61cd2
SSDeep 49152:yVhP9EodbA/C2QOY1eT5MWqdrsYEFdhtaAFO3FPoR3txp8oBp/QqxfFNK3Tp:6hFEo+xTuWqdrsYCTk6b3tfhPIqxfu
TLSH 4ED52399A6F605B4D833C3735FD3E0AD75263B844B76CE17B6CC2A108E62A54583B339
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.Olk
.mRJ
.,}F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.Olk
.mRJ
.,}F
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙