Malicious
PE Executable
MD5: 47a4f35908f85c4a3fbe536341989d7a
Size: 341.5 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 47a4f35908f85c4a3fbe536341989d7a |
| Sha1 | 6c05f1d4a1d5ab6414f2df877978cf253c2f2d30 |
| Sha256 | 931ce3beac7484c2bab59eb90ee0b8230823a2f7b0dbfd6ffd4296767b0640b8 |
| Sha384 | 0ddd1efa1e0226277f738c265cd36d24a75206b597738535d78e2a19ffdd5e1e4360f7a9869cb9d96851286bd7f6445c |
| Sha512 | 577d84c772a572478589dc18fc2b03462a99bc00ee0e08c0becaef26a73e9862e74e5310c5d36f349707d637cf314a1bb97cb33a6bb870be1e3a158dacd779c4 |
| SSDeep | 6144:8n+06yirywPV6q6KRIb1qkNMJ5A8S0+z2oQ9UeFMr:Ah6yiBP3DkK5A8S0+2ouU |
| TLSH | EF746C21B291C236D5AE1130A679DB7B0D7D78310BE5D0CBA3D04E6E1E217E2EE3475A |
PeID
MS Visual C++ v7.0 DLLMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamVisual C++ 2003 DLL -> MicrosoftVisual C++ 2005 DLL -> Microsoft
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll
Shape
pe:dll
1 nodes
| Config. Field | Value |
|---|---|
| C2 | https:huhuhuhuhuhuhuhuhuhuhu |
| Botnet | t_no_ahuhuhuhuhuhuhuhuhuhuhu |
| UserAgent | _CB&pthuhuhuhuhuhuhuhuhuhuhu |
| [Configuration Offset] | 0x0huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| C2 | https:huhuhuhuhuhuhuhuhuhuhu |
| Botnet | cal_tkhuhuhuhuhuhuhuhuhuhuhu |
| UserAgent | /commohuhuhuhuhuhuhuhuhuhuhu |
| [Configuration Offset] | 0x0huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| C2 | https:huhuhuhuhuhuhuhuhuhuhu |
| Botnet | t_3rd_huhuhuhuhuhuhuhuhuhuhu |
| UserAgent | roghuhuhuhuhuhuhuhuhuhuhu |
| [Configuration Offset] | 0x0huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| C2 | https:huhuhuhuhuhuhuhuhuhuhu |
| Botnet | ogin2.huhuhuhuhuhuhuhuhuhuhu |
| UserAgent | ^1Y%?huhuhuhuhuhuhuhuhuhuhu |
| [Configuration Offset] | 0x0huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |