Suspicious
Suspect

0d60097c07241a4a98fb18196d21d75f

Share on LinkedIn
Print
MD5: 0d60097c07241a4a98fb18196d21d75f
Size: 433.66 KB

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0d60097c07241a4a98fb18196d21d75f
Sha1 32eb1eb04ffdce6012e24467778552999cf7f011
Sha256 91847a5075fd0e938f4aec3a23a4437c6445f4eefc201fa288e0d1513edf0561
Sha384 d9e836560f6c710568e9d3e48f4c8ad81cfbb6a21e068f44f3d1735a6956b37cef2ecebcebeb87fdea218ead9891cbba
Sha512 27ca6f4c4f390acb6c9e2002f03cd20d7a4fb4fa0de2f79f2e26a977508f185da5888096da2ab784e78b420c0734c54a7a0f50201d69a09df16144d76601f916
SSDeep 12288:DyWZpwVcYJYkYJ+UmoaQi2oAkpDZAUqYk9nhDXvU:DyWZpDiAxad2oAk36nBhDXvU
TLSH 46942306FA31C57AE2B20174DDB56D3B4EBE8533866A3D43479074997E614C2D71F382
PeID
Microsoft Visual C++ v6.0 DLL
Overlay_1190720c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[NSIS Installer] @ #00009608
Overlay_f2c006fe.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.didat
.mrdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
17476
ID:7777
[Authenticode]_00d141fd.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
PAGE
INIT
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
[SETUP_DECOMPILED.NSI]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 6

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_1190720c.bin (395257 bytes)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙