Suspicious
Suspect

9718604070d0678c900c845a093753b5

PE Executable
MD5: 9718604070d0678c900c845a093753b5
Size: 6.4 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9718604070d0678c900c845a093753b5
Sha1 0e38e16bbfab79af1b03a7d2c7dbfa6cc5a3117a
Sha256 c0b9861aa16d84af9060aa4f09bee129e769978bbe4065c9edfa90be532d2778
Sha384 e608f53cfbbb08a15ad1f42aa685d07ad96a51ba03ce27f330732ce8c7c0b4dc33bd632250a026c6d0fb52bef926d67c
Sha512 a5bc5779514ddb15cb88eee82b4cf1a97365f2499504f618d453a4d22ab6b59e7565f082ad86732d2268ae2d656126eda75fab106b9187e63a33e328890c0133
SSDeep 49152:dgLG+l8+OMrdSPvq2eev2holHSyF9/KhyDlGJnUx+E:d28+OMrMPvdejY
TLSH 8956D82973C88A21C873013A5D58F4C4FE355D3321659D2A31CE3EA31B76DA2B3AFA55
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLL
Overlay_7278ab94.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.data
.rdata
.rsrc
.tls
.pdata
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs
Shape pe:exe>scr:vbs
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_7278ab94.bin (4831951 bytes)
Overlay_7278ab94.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.data
.rdata
.rsrc
.tls
.pdata
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙