Suspicious
Suspect

4f1d4fda1144646990ce36efc915d43b

Share on LinkedIn
Print
PE Executable
MD5: 4f1d4fda1144646990ce36efc915d43b
Size: 379.03 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4f1d4fda1144646990ce36efc915d43b
Sha1 b4cccb07fb11d53156e975edad2767ef519efc39
Sha256 02469c593ecd42b98fd30db086bfc49c9a486d123085a626cf2ab247d7003e65
Sha384 dd798f7ce21c338ce6f53c5c4e88331ce2855607809c4bfbe322e49eb199b95a7167dd241849234c219a5c28fecbb077
Sha512 86e3ffc225f86e7358da0cb12613b29fc8f145b67696bfcbb80811c91c8fa78ae9700832962ccb26697e7248184154464a8644ad01343903a1df0f88e61d623b
SSDeep 6144:/mGIhCrl0WKxHId8CSkgTUok86+vQj63bywq7YblDXsBbhq56zOa8:Om0NxodvSke38mWwNDahqPa8
TLSH 4984CF93FA80C2AAFC3D4C75D9A352341B72ADB696858F4357D875123FA3280353B42E
PeID
Installer Nullsoft PiMP Stub v.3.0.x - A.S.L Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #00031608
Unmistakingly
citharoedic.fej
friherrer.top
kommutativ.bid
reportage.tro
spermaets.syl
unsharply.pos
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
[Authenticode]_df996d1f.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_BITMAP
ID:006E
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:0068
ID:1033
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5B558 size 4928 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙