Suspicious
Suspect

1467f5f92f91eb363cfaf1c902ffb0a2

Share on LinkedIn
Print
PE Executable
MD5: 1467f5f92f91eb363cfaf1c902ffb0a2
Size: 10.42 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1467f5f92f91eb363cfaf1c902ffb0a2
Sha1 4ef9c4468fd4f3ac58a083393e64dcc093ebb3c2
Sha256 c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a
Sha384 d7a055f34a175b3b69984173ff56b8a283b6e7944e548a9dc700fb967726f220dd2a91ecf6bbc478e029fa5c22fb4f85
Sha512 5cef73fffcbd97c014227384a243bbfe2b439ed63c4d907458c36efcbc4f269fd71433e739e2ba2391aa1d2161c891dbc69214c3b66b1c734aae2fd3e3d8bdae
SSDeep 196608:+ppHDvWq069kN6ncZi1UGS4M4RoLEvL10dshbJC7X9V0IvTahm8x:+pp2GK6cb0MNL+p0oy91vWhNx
TLSH 61A633533B46A4F1E02A9A316FC7DB0702B7C77D1615CE7B61921ECEACA30A11A475CE
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
pipelineparam16.db
servicemgr50.ini
[Authenticode]_5da9e0f9.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:4147
RT_VERSION
ID:0001
ID:4147
[Authenticode]_12212359.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
REGISTRY
ID:0065
ID:1033
ID:0066
ID:1033
ID:0067
ID:1033
ID:0068
ID:1033
ID:006A
ID:1033
ID:006E
ID:1033
ID:006F
ID:1033
TYPELIB
ID:0001
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:007E
ID:1
ID:5
ID:6
ID:7
ID:8
ID:9
ID:10
ID:11
ID:12
ID:13
ID:14
ID:16
ID:17
ID:18
ID:19
ID:20
ID:21
ID:25
ID:27
ID:29
ID:30
ID:31
ID:36
ID:1028
ID:1046
ID:2052
ID:2070
RT_MESSAGETABLE
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
[Authenticode]_4602fdbb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_67d13870.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_651cbebd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_df1cbf95.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bf3dd1e5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_9f8adfeb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_bbd25734.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_3a73181f.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
Overlay_9dc11e81.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
ID:0005
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 6

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_9dc11e81.bin (10229728 bytes)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙