Suspicious
Suspect

7aee848e4abbade4c36d943f486ea8a6

PE Executable
MD5: 7aee848e4abbade4c36d943f486ea8a6
Size: 11.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7aee848e4abbade4c36d943f486ea8a6
Sha1 6e843abd39529f25eccf19154dac70a5e1400547
Sha256 b84a282b1e648b1de04fae7d7b6aedca461eb2be96116b91f63ec0475fa9fb7e
Sha384 6a52d0e8a529450845c828662a8d4f1b6019eb762d7f72686f4eaa4aabf51da4674fb1e1caf777ee2908fd5693b77e3c
Sha512 fe0b823d881c2db892cd97318a1a74335ecccc9db69cfa96b9f374f10fcd9f5b7170e40929e4eb17a1b95de29b691a5257b7314b84c54d330c1df3c9cd18fbc8
SSDeep 196608:8aZk+wDP+CHD4a+KFwUUUx9Y2NPFOsti7A95rIUsFp29XaIT030Hy0SarlZr8s2z:OnSmzZFw5S9pE7Asjp29qIT0jarlZr87
TLSH A8B63347D9778DF0CA330B3890D2196B3305980E485AF4C9F609277ADAF35AADD2879D
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
[NSIS Installer] @ #00018608
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
[Authenticode]_d41674fb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_DIALOG
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xA88B78 size 10352 bytes
[NSIS Installer] @ #00018608
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
[Authenticode]_d41674fb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_DIALOG
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙