Malicious
PE Executable
MD5: 8a1918412cd72ae23409f3b3541f8731
Size: 2.28 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 8a1918412cd72ae23409f3b3541f8731 |
| Sha1 | 86b794056c950f100e25d1ac64d6bed8a9a65006 |
| Sha256 | 1179e6a525f9eed567af44c6c5ff6a413e7cdecd8fabd47623cdbbf325bffd88 |
| Sha384 | c010b3baf61b73d8f8e3ab87d2348e4193a9b7e503db6fda55855e517a85128f6651e7478f341649bed2c5c07d1f56bb |
| Sha512 | f8e3761d7ac47e93ab7db153898160e3858d79d009d1cccbe5459eec051fb037527ddcddeef7986e9232cd45d23aec061a7de808ee13cc1253147196019454e6 |
| SSDeep | 49152:NC6A9HMwruo9MzsvkwLBXK+EPZhYk3Ps1xvfG4mhyoU:ishNz6BatcUs1lf5mhy |
| TLSH | F4B5330213E484E6D67D6331CCF256036A72BC429736BBAF22A5554A2B339C1AD3375F |
PeID
Microsoft Visual C++ 8.0 (DLL)
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 1secondary ignored: 6
bin
4img
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:autoit>pe:autoit
Shape
pe:exe>pe:autoit>pe:autoit
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: wextract.pdb |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential