Suspicious
Suspect

1467f5f92f91eb363cfaf1c902ffb0a2

PE Executable
MD5: 1467f5f92f91eb363cfaf1c902ffb0a2
Size: 10.42 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1467f5f92f91eb363cfaf1c902ffb0a2
Sha1 4ef9c4468fd4f3ac58a083393e64dcc093ebb3c2
Sha256 c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a
Sha384 d7a055f34a175b3b69984173ff56b8a283b6e7944e548a9dc700fb967726f220dd2a91ecf6bbc478e029fa5c22fb4f85
Sha512 5cef73fffcbd97c014227384a243bbfe2b439ed63c4d907458c36efcbc4f269fd71433e739e2ba2391aa1d2161c891dbc69214c3b66b1c734aae2fd3e3d8bdae
SSDeep 196608:+ppHDvWq069kN6ncZi1UGS4M4RoLEvL10dshbJC7X9V0IvTahm8x:+pp2GK6cb0MNL+p0oy91vWhNx
TLSH 61A633533B46A4F1E02A9A316FC7DB0702B7C77D1615CE7B61921ECEACA30A11A475CE
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
pipelineparam16.db
servicemgr50.ini
[Authenticode]_5da9e0f9.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:4147
RT_VERSION
ID:0001
ID:4147
[Authenticode]_12212359.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
REGISTRY
ID:0065
ID:1033
ID:0066
ID:1033
ID:0067
ID:1033
ID:0068
ID:1033
ID:006A
ID:1033
ID:006E
ID:1033
ID:006F
ID:1033
TYPELIB
ID:0001
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:007E
ID:1
ID:5
ID:6
ID:7
ID:8
ID:9
ID:10
ID:11
ID:12
ID:13
ID:14
ID:16
ID:17
ID:18
ID:19
ID:20
ID:21
ID:25
ID:27
ID:29
ID:30
ID:31
ID:36
ID:1028
ID:1046
ID:2052
ID:2070
RT_MESSAGETABLE
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
[Authenticode]_4602fdbb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_67d13870.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_651cbebd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_df1cbf95.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bf3dd1e5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_9f8adfeb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bbd25734.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_3a73181f.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
Overlay_9dc11e81.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
ID:0005
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 6

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_9dc11e81.bin (10229728 bytes)
pipelineparam16.db
servicemgr50.ini
[Authenticode]_5da9e0f9.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:4147
RT_VERSION
ID:0001
ID:4147
[Authenticode]_12212359.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
REGISTRY
ID:0065
ID:1033
ID:0066
ID:1033
ID:0067
ID:1033
ID:0068
ID:1033
ID:006A
ID:1033
ID:006E
ID:1033
ID:006F
ID:1033
TYPELIB
ID:0001
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:007E
ID:1
ID:5
ID:6
ID:7
ID:8
ID:9
ID:10
ID:11
ID:12
ID:13
ID:14
ID:16
ID:17
ID:18
ID:19
ID:20
ID:21
ID:25
ID:27
ID:29
ID:30
ID:31
ID:36
ID:1028
ID:1046
ID:2052
ID:2070
RT_MESSAGETABLE
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
[Authenticode]_4602fdbb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_67d13870.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_651cbebd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_df1cbf95.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bf3dd1e5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_9f8adfeb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bbd25734.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_3a73181f.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
Overlay_9dc11e81.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
ID:0005
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙