Suspect
PE Executable
MD5: 1467f5f92f91eb363cfaf1c902ffb0a2
Size: 10.42 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 1467f5f92f91eb363cfaf1c902ffb0a2 |
| Sha1 | 4ef9c4468fd4f3ac58a083393e64dcc093ebb3c2 |
| Sha256 | c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a |
| Sha384 | d7a055f34a175b3b69984173ff56b8a283b6e7944e548a9dc700fb967726f220dd2a91ecf6bbc478e029fa5c22fb4f85 |
| Sha512 | 5cef73fffcbd97c014227384a243bbfe2b439ed63c4d907458c36efcbc4f269fd71433e739e2ba2391aa1d2161c891dbc69214c3b66b1c734aae2fd3e3d8bdae |
| SSDeep | 196608:+ppHDvWq069kN6ncZi1UGS4M4RoLEvL10dshbJC7X9V0IvTahm8x:+pp2GK6cb0MNL+p0oy91vWhNx |
| TLSH | 61A633533B46A4F1E02A9A316FC7DB0702B7C77D1615CE7B61921ECEACA30A11A475CE |
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 1secondary ignored: 6
bin
6Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>arc:7zsfx
Shape
pe:exe>arc:7zsfx
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_9dc11e81.bin (10229728 bytes) |