Malicious
Malicious

4ab9024831a3c786ba3b5e98474dcc2b

Share on LinkedIn
Print
PE Executable
MD5: 4ab9024831a3c786ba3b5e98474dcc2b
Size: 5.13 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4ab9024831a3c786ba3b5e98474dcc2b
Sha1 07d3110dac6559428e99192d2d06fe64d4ea20ba
Sha256 243c5a1cb8cead1aa028d7470e63fa33b313ad6434c57b249008daba43c0f71f
Sha384 e37882db58e5ac9131c1212ce7b6a7c5cfedb34f9fcae36c1ef9634d567a7cbddd6a5bf9a4460694ce0266ae77664256
Sha512 2fdaf899266190233ef5b8d5a72a9e6d6799ada441e19e455384a2b5d797e097d6f02cc04c966471e38d90474df1859524356bc39e172a202363e822967cc8ba
SSDeep 98304:BVLnrOHTVjkcMUgohT3higkVgohT3higk:TLnrOHT5q
TLSH 5E365B22959017ECE07FC179898A5E12FB317009136567EF09D045A3AEA7AF0BE7F352
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
HYPE_C2CFG
ID:0001
ID:1033
RT_RCDATA
ID:00D2
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
ID:00D3
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:rsrc>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
An error has occurred. This application may no longer respond until reloaded. Reload 🗙