Malicious
Malicious

32bcff75191b48284e927db09b0a5fdc

Share on LinkedIn
Print
PE Executable
MD5: 32bcff75191b48284e927db09b0a5fdc
Size: 3.52 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 32bcff75191b48284e927db09b0a5fdc
Sha1 c7a9d5f6b526b726b50fa1e02d46683e0ffefede
Sha256 85ad0b4124b657a35a01d820fff4325f5c4c3ceb60615ad54c4a0ddbcadd590c
Sha384 24a715d91271866daa3882b938c08aed892cd0cb9e6feaef2c743f2ea43fdd47ab82f305e2ae0058f173d42a4f0ad793
Sha512 7100abdeec2a7f23d9ec2b2f273f99008f2a8cadcdfe44f2439cc0184a97491ad3466f3ccec4c677b0d77163f1f8896e1ee34dfd911d39136bf92de91ef535e4
SSDeep 98304:ya7S0srRwqG3Mm1UCjg7AO8jLbrgZCaRsR4:ZXsrRJGcm0QNaWy
TLSH 0FF52381B9D28171E5321CB75A799711E8BCBD603B2A9ECF23D42A5DDC718E0EB31352
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
JZdGPOJFXyRyGvkSXg.FgcAj3i5UGdHrDMhjH
VVPEM3Si2oWtammMq3.oTaBNCosIslfm3uQPP
HslAmZuJNYuSPWC9MT.OtuhOF2e3FtUHKaF8M
1isS63KQToqHw5pNyJ.2SlHcdUaw3r4JlUZJ6
b30siKDSB5p4uqhmtN.73S9OtqOnyLtC2edPK
019n5awL9q9MuQOGNM.3NSrf0cINCWHwrFyC3
0M2YrrdyC3g9VftuNjEJgsyay52vpIVSGf.vbe
Malicious
0M2YrrdyC3g9VftuNjEJgsyay52vpIVSGf.vbe.decoded.vbs
Malicious
fypk0CHWXTTtMieyotgRl6BP7.bat
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 3secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>arc:rar>pe:exe>pe:rsrc>bin
Shape pe:exe>arc:rar>pe:exe>pe:rsrc>bin
malicious 5 nodes
Path pe:exe>arc:rar>pe:exe>bin
Shape pe:exe>arc:rar>pe:exe>bin
malicious 4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_48aacb67.bin (3194229 bytes)
Info
PDB Path: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙