Suspicious
Suspect

2dbacc3dffa948fc32bdc6dec93e1324

Share on LinkedIn
Print
MD5: 2dbacc3dffa948fc32bdc6dec93e1324
Size: 192.73 KB

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2dbacc3dffa948fc32bdc6dec93e1324
Sha1 ac856b31c0d7684c6c10e0d2a0c0bea0c9e1f057
Sha256 b90ccc2ca08d4a954598030b995408c334e60fea5106dfaf96bf49e5b37fb145
Sha384 b4e4e2eef5bedee19fb076a8b00b35004440fefc309faa3d63cc3f9f7549621c0fedcff222465b1f7ef0f204bdb76c94
Sha512 a0e7cd149775a4a35a13fd22daca2fbab6ddd6e87a5a1b71e676e192e14a679726504b2a94371788396974176bfd6778c5fb9d04892241015f0874705f3e914f
SSDeep 3072:rXK9qKo9bH1ruHvyXpKCR9ygNVIPh8c/S8kaHayGC2u++wRLwI:rXFKo5yeQFuVc8cK8HHaDC2n+iLwI
TLSH D11401116AA0C473E5231772DAB69EAB17F56A201624870B77402FDABF73183CF2F549
PeID
Microsoft Visual C++ v6.0 DLL
[Authenticode]_77868a92.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[NSIS Installer] @ #0000FA08
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Belbsrammerne198
Septimakkordens.ini
cambodjanerne.ini
[SETUP_DECOMPILED.NSI]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2E7A8 size 2352 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙