Malicious
Malicious

29fc322ceb5f47f5596018e502a3f619

PE Executable
MD5: 29fc322ceb5f47f5596018e502a3f619
Size: 602.11 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 29fc322ceb5f47f5596018e502a3f619
Sha1 25718aa0f21434181c76f8247b1cf0dd56c980ca
Sha256 6336b1a886d5b84480eade15f0c9b9fb510fe0f02a8501b5ab08229075985086
Sha384 124518f20daee5f06cfcb1875b92561bc568046fb9d7b8601be7e0ae893da8d45c854d80c5abf644727b4f61fe433d73
Sha512 d0ebb42b89b5aea6a7b581180cde6e91918696da001d0042ab9f4f193c41452341b55fd6f5a5fb9a9dac5d62c875d2cc0c802598f651521e224cf8b570228e05
SSDeep 12288:TEzPL/FzLf8SRjCGkbtsh6oGEiQo/BjlAVolFPFtUfpZs:4zPtfhjaG6JuGBmqvws
TLSH ACD4F11553E800A6F0B66B7498B24A9799327C21AFB492FF13C4A17D1F336C5A536F0B
PeID
Microsoft Visual C++ 8.0 (DLL)
fsquirt.res
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.rsrc
.reloc
Resources
Malicious
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:2057
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:2057
ID:07D5
ID:1033
ID:2057
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:2057
ID:004D
ID:1033
ID:2057
ID:0050
ID:1033
ID:0053
ID:1033
ID:2057
ID:0055
ID:1033
ID:2057
RT_RCDATA
Malicious
ID:0000
Malicious
ID:2057
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2057
RT_MANIFEST
ID:0001
ID:1033
GitHubDesktop.res
hlsw-portable.res
ImagingDevices.res
IMCCPHR.res
imecfmui.res
IMESEARCH.res
IMEWDBLD.res
IMJPDCT.res
IMJPUEX.res
IMTCLNWZ.res
isoburn.res
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>scr:ps1~T1027~T1059.001
Shape pe:exe>pe:rsrc>scr:ps1
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: wextract.pdb
Deobfuscated PowerShell UNKNWOWNmalicious
. (Gethuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
fsquirt.res
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.rsrc
.reloc
Resources
Malicious
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:2057
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:2057
ID:07D5
ID:1033
ID:2057
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:2057
ID:004D
ID:1033
ID:2057
ID:0050
ID:1033
ID:0053
ID:1033
ID:2057
ID:0055
ID:1033
ID:2057
RT_RCDATA
Malicious
ID:0000
Malicious
ID:2057
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2057
RT_MANIFEST
ID:0001
ID:1033
GitHubDesktop.res
hlsw-portable.res
ImagingDevices.res
IMCCPHR.res
imecfmui.res
IMESEARCH.res
IMEWDBLD.res
IMJPDCT.res
IMJPUEX.res
IMTCLNWZ.res
isoburn.res
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
. (Gethuhuhuhuhuhuhuhuhuhuhu
29fc322ceb5f47f5596018e502a3f619 › Resources › RT_RCDATA › ID:0000 › ID:1033 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙