Suspect
8b833319a80ffc1879722fb1455fb419
PE Executable
MD5: 8b833319a80ffc1879722fb1455fb419
Size: 299.01 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 8b833319a80ffc1879722fb1455fb419 |
| Sha1 | 3b3bf71a90397816cc6cb8f17d5dd82355fbcb38 |
| Sha256 | 5ce68cd389e40ef322cbbc76361b78e4ab9cd7b8bd4942b903b9bdbd338609df |
| Sha384 | 3df2ebffb139089ff33d018add8c1d1f7b36d3c0617b9b89cb64c90afa5b20034be4e8f8caa93e1d2c8559a5816ab9ae |
| Sha512 | 95c89b006aac3f9f4eeb607045972fc6f35ac67092a9d58ee9e8f0129d3658d2a98aea6c09ae0b42df54b5df062007640b60e3def3c53bb149ee44037516a97e |
| SSDeep | 6144:h6R+qTbitQ5DH6p03wJt82lfFmi+oypDe/q4vTNkV3huTYANwEROc:0+q3itQt60gJt8EfFOoypa/q4velhu9D |
| TLSH | 3B54226FF7EC5A0CE77F32726D451869D9B0F84A955ED23CC0E1A1C88A4C6C91209B7E |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 1secondary ignored: 6
bin
5img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>arc:zip>html
Shape
pe:exe>arc:zip>html
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | TaleWeave-Setup.exe |
| Full Name | TaleWeave-Setup.exe |
| EntryPoint | System.Void TaleWeaveSetup.Program::Main(System.String[]) |
| Scope Name | TaleWeave-Setup.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | TaleWeave-Setup |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 37 |
| Main Method | System.Void TaleWeaveSetup.Program::Main(System.String[]) |
| Main IL Instruction Count | 152 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.