Malicious
Malicious

547f24096e74bfe49d1682b8aecb6fde

PE Executable
MD5: 547f24096e74bfe49d1682b8aecb6fde
Size: 7.35 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 547f24096e74bfe49d1682b8aecb6fde
Sha1 390edc87148e627f812bfda0bb14f038d259d5f3
Sha256 9e2f886322137391fdfd8555e5a2e317a3c507b51e897c53273d5d696531cc12
Sha384 26fde89d19242fd9b20741e98c8b138307152964f25260b424897815c25652eed3ec08f30dface60852ba81bbd0ba8b8
Sha512 216d0d656343bcafa5efc023231d1d75388d99a85dafdacf140f68203dd0cbad7376835151936aed442ce58c98cb47afb35cff3b7746eb28eb0736e2538488b3
SSDeep 49152:FYiOR0xPMb33yvgHx8A5OLdfUQtn+eiKxF9CeNqLkL7a/kxlD3yTaXd+0il3ZbaG:g
TLSH 917612562ED5AB6EC402A0FC221A9571F5DD9EC8D3ADD3E1D836E832329847CD2375B0
PeID
Microsoft Visual C++ 8.0 (DLL)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs~T1027~T1059.005
Shape pe:exe>scr:vbs
technique2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_e4f7b7cf.bin (7325417 bytes)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙