Malicious
Malicious

491757de5a46115ed5d9ca8fa04414a4

PE Executable
MD5: 491757de5a46115ed5d9ca8fa04414a4
Size: 5.38 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 491757de5a46115ed5d9ca8fa04414a4
Sha1 0ae98b6923dea5c1c2c6e027d8b234a3a833ccd1
Sha256 f975c5077bd774863457e039c3fda9463cc954d891fbf9546763bf38fbd755ea
Sha384 ab56761c5a2e76b3ed30fcf32ef985328dcb847ff0e9b4cf27956ebff7807bc251994f78314e709a068df83947a38783
Sha512 732e39b76b6806c8ef70ebfa232623b089db7a30f48992e35f948acec1a56affb42abad2160d00938454d0955cf2b52841c3e0ce10a39bf8837b6522b9ea54c4
SSDeep 98304:HG8xo4tZLOuLPATULj2gohT3higkVgohT3higk:m8xnrJ+q
TLSH EA465A22558017E8E17FC179898A5E12FF327009136567EF099045A3EEA7AF0BE7F352
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
HYPE_C2CFG
ID:0001
ID:1033
RT_RCDATA
ID:00D2
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
ID:00D3
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:rsrc>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
HYPE_C2CFG
ID:0001
ID:1033
RT_RCDATA
ID:00D2
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
ID:00D3
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙