Malicious
Malicious

389055b0def3f57fc15695e1e7623534

PE Executable
MD5: 389055b0def3f57fc15695e1e7623534
Size: 8.06 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 389055b0def3f57fc15695e1e7623534
Sha1 a12c6aaccc3dcb8a22ba3bfe5d19f49417ce5136
Sha256 98ec6a83a313319730bd143f6ce63ddce4389f638ad598c630faeac804755555
Sha384 93a34b02605a602bb3eaac40c6f7a9e57921f20f4330c059ac70080dcd4706030a363a5bdff304bb2b0363834789875b
Sha512 9dbf31093bc6e1b3cfd624d19128c2e359d97d7664257b0c2703fcd18412ec06a21a249a3086acb0ea25d3ae65342402392208ee8145543656214ae30ad4ebd0
SSDeep 98304:+yhg0v/sH7wSkSUx3TSQ9n1Z76br5M4vIMPKm:+yhrXq7kbTt1Abd/LPKm
TLSH 0E86BE037B81C1B0D496EA7AC4B6415177B87C4D833433AB6EA5A9303F263D1B67AF64
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_0d06c188.p7b
Overlay_ce5365c7.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5BD800 size 8080 bytes
Info
Overlay extracted: Overlay_ce5365c7.bin (2033664 bytes)
[Authenticode]_0d06c188.p7b
Overlay_ce5365c7.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙