Malicious
Malicious

57d5080b9762a6fac6aa8d7612373da2

Share on LinkedIn
Print
PE Executable
MD5: 57d5080b9762a6fac6aa8d7612373da2
Size: 2.83 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 57d5080b9762a6fac6aa8d7612373da2
Sha1 87d01491138bb99295a1a46ca84f289fc563ef00
Sha256 b1e3240894123ea146b1bbfdb71581a0fc29fc33592e9cb4e320e88c49419ecd
Sha384 33d6234f9480c4948853b8c4f260cb6a6b115c396cdf15915227178b7407cd821385c751e41668d32c39965124a6d4cc
Sha512 3d8b13d7f28adce1c0b5ebf25129c5bffc36194a8597f196f371aef6aac57e28cc64d3f554bcedd17c54fd484fbf0ac4c44779af03050d5b951e749ed3cb78ee
SSDeep 49152:YmgMvWP8/DHlFHLb96eiWgPmwm+QvyiWYD80kFRYJB:YzLSd6BWgP6raiRkFeL
TLSH 85D58D1A7CD589FAD459133249AB79A17BF4BC049F3223D32E94F1B82EB6AD41E34701
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙