Suspicious
Suspect

7cec47740ae2e3a5914bb46bc2d0ffc6

Share on LinkedIn
Print
PE Executable
MD5: 7cec47740ae2e3a5914bb46bc2d0ffc6
Size: 396.47 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7cec47740ae2e3a5914bb46bc2d0ffc6
Sha1 154484d6e6775ebef39dfdf7d3ca6c2f2a99d4fa
Sha256 b811dce1aae1c0e0da249d5eb19dfd5b2640214627c9603b97f6f79c25a22e97
Sha384 c5de40d0e248c4553bbc86b10b1effe3e52f1ca4a43f20d7f3e0b6464cdbb12825a64a87e648bd6e0c4b8b2cb0398534
Sha512 a473acfd64f7f6aa52db5419dc00fdd0b8d9ec027b9b876466fff8251bd6190b7186a6828e40d80f296ba94f1d98aa86987d581c2fd7d474c21c9839e29f7f32
SSDeep 6144:8mGIhCrl0WKxHId8Cc3IcgAYhXLnun8q+Jlq56zL:rm0Nxodvc3lgAyan8pfq2
TLSH 1984CF93F980C6AAFC2D4C75D5A752301B72ADB696858F4393D879123FB22C0353B52E
PeID
Installer Nullsoft PiMP Stub v.3.0.x - A.S.L Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #00031608
Centerskolers
citharoedic.fej
Lufthullernes
friherrer.top
kommutativ.bid
reportage.tro
spermaets.syl
unsharply.pos
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
[Authenticode]_353d0079.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_BITMAP
ID:006E
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:0068
ID:1033
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5F8D0 size 5096 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙