Suspicious
Suspect

6e579b5b23c9c2ba596e4cd63641ec8e

Share on LinkedIn
Print
PE Executable
MD5: 6e579b5b23c9c2ba596e4cd63641ec8e
Size: 396.13 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6e579b5b23c9c2ba596e4cd63641ec8e
Sha1 c1b483ac164cc5c6967fb741b389145e697e44a1
Sha256 223082d8fb6188b357e833ec5abba36bde4e371bd3a8eac2a2e2511c70358bdf
Sha384 48b911c0212e30bd25a172ee9679399144a90294bac8469f44855e9d7514a15de7ba19cfbc6a34a190e69b486d08e2f9
Sha512 349e1f1c4aa7babcd1c616096cd057f02b68edfe3589b7e0182c4a5cfe965a7769a41f37164875435d5c5f7a0e3473c397d9d7a0cc974c33f359c84342ac042e
SSDeep 6144:FXFKo5ClMKn912RmsFhHVPulTHe5LL45tOZm7I9gw7dlLta:FXE2dHVPut+hEDOZm7I9h
TLSH CD849E14A785C85DC29016BA5A339F9914BCAE017A5DCEA362D07DBC24B4FF198CE1CF
PeID
Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #00033608
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Overgood123
Tnkepausens.lon
Hermitlike
slidendes.arv
[SETUP_DECOMPILED.NSI]
[Authenticode]_3bdc1a2d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_BITMAP
ID:006E
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
RT_DIALOG
ID:0068
ID:1033
ID:0069
ID:1033
ID:006A
ID:1033
ID:006B
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5F920 size 4672 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙