Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 493ee8238d9885013cf12c613b7847c7
Sha1 0abaf8d53e0974b9ee69f1d2e72e6ac46154012e
Sha256 49347466b098ea9e178f6f35a3efc78da11ede962cbb3a26bd9758e64031eb69
Sha384 9177f5f8e2e9ebe0666b7afcc824d7a7a81aad0a627273537b18a0c8f0f2aaffcb6fa9b2b84c7b47b9804d9fd7a5f15e
Sha512 42c1acfd1f12b445d378ca1211ce5ca95c98fe41ebaa2fbb86755bd50061ff9b0098ed5257844327ba37976ca7479b145f7c9f202fe549a40cf8336c0bef4df6
SSDeep 98304:zClvSIQotY1jJ6I/EQ+LxsE3WajDxlaEY:OlvSIQDbcQ+LxzmaJlHY
TLSH 0257294AFFD1CF42E9A6867898775B103373E8A54B71C3C7125461382D973C88EF2A99
PeID
HQR data fileMicrosoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_24f589a2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 2secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7z
Shape pe:exe>arc:7z
2 nodes
Path pe:exe>enc:b64
Shape pe:exe>enc:b64
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x1C25000 size 10704 bytes
Info
PDB Path: K&>.yC?B
)>O 'L>[??.xJ>Hf?y\PD>!?M???L>??|b=})>???\? >?v?c [1>H'????)>????dL?>Z?|??F>??N?i?;>??_??j+>??y??C>?O@?L?)>??uzKs@>??D>?H??e?@>?5?A?3>N;kU??r=C?A	? >???	p?.>E???K>V???R?>>?e?
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_24f589a2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙