Suspicious
Suspect

861a9b7ff7e91010cf002fb2b669bf1c

PE Executable
MD5: 861a9b7ff7e91010cf002fb2b669bf1c
Size: 813.8 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 861a9b7ff7e91010cf002fb2b669bf1c
Sha1 f8715cf08dfd25ac10accf8f8d930d9cfbb606ce
Sha256 cfd5919b1f3d3add639bd324514c39f3807f93bbd75eb8efd576c72d26eea1bf
Sha384 27ba80c763006555aba55da73bcb113d6c589549557d4e86f13747a67aedf73db2931e0597a1695a9aa2b34ff7f87af3
Sha512 240eed997dc30ca2a95fe9c298b80bdef19a9e7e973da21b7367acaa25d7ab90f3ab1c30f1b4b7a383aaeca2449974be31aba7f10230fe688a892aae3137fc7b
SSDeep 12288:u++ri4BlgZomk0cuS1RhLsySWmFN0x1gVwY4pSU5HTRcMQK:u+31omcjay3qNZutAU/c7K
TLSH 0F05272A2EBA4E89F6E1D034D55F82713271ED4B091A2C5B21D63E6C343ED5DC4C9A3E
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
[NSIS Installer] @ #00060008
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Embordering
Brugsforeningen196.jpg
Brugsforeningen196.jpg-preview.png
Korrektionerne194.aak
Nonlactic.txt
klpulvers.txt
[SETUP_DECOMPILED.NSI]
[Authenticode]_bb11feaa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xC61B0 size 2360 bytes
[NSIS Installer] @ #00060008
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Embordering
Brugsforeningen196.jpg
Brugsforeningen196.jpg-preview.png
Korrektionerne194.aak
Nonlactic.txt
klpulvers.txt
[SETUP_DECOMPILED.NSI]
[Authenticode]_bb11feaa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙