Malicious
PE Executable
MD5: ffef04a0b56e2b32c56a429e8def03a3
Size: 3.84 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ffef04a0b56e2b32c56a429e8def03a3 |
| Sha1 | f6158a3b99febdd039bdf2a8d9c6e1354afdd664 |
| Sha256 | 68c609de10fb10b4349cb615a15fd4c6c3871a3f26e85184d31f4bf570efd1c7 |
| Sha384 | 270e2b8a73e016f810e4271ce1916c732a871662599c0958aaa5710d218085f5d83a2fe3c5352df947cc1ac07b2fe180 |
| Sha512 | 29a7d4dda97b35a32196c4eeeb23355fad3ce8a984955b7c9513c12054107207c0e911bc798823a219193b5a971609010564095dc986ec2dc76fd48f558cecf9 |
| SSDeep | 49152:kL8sbr2yWtpErR54BQIyLY/LkFKaSRQTVIySYrBR3N2h7WTCriN7oGyD+wQ+e+pM:kp+pYRSQ432L |
| TLSH | A0067C03EDA21CB6C05963328CBA52527B7DBC4A1B3223D32D50B67A7FB6BE45835714 |
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll~T1027~T1055>bin
Shape
pe:dll>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x3A88B8 size 2416 bytes |