Suspect
7Zip SFX Archive
MD5: 98f00e36daaf4c4bae91031d4b53ea9b
Size: 6.34 MB
application/octet-stream
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 98f00e36daaf4c4bae91031d4b53ea9b |
| Sha1 | 6c19930c2b6b2ec49b42399dcd8e477de347c010 |
| Sha256 | 46ced738ab9a9a37df3e36c6a8603742f26783f0be2fa845bdec10b5ddb50bfb |
| Sha384 | afa2abb3b40e5a04245d7d6dbcfb5171c2f3cfa639063d359cd38bd8b77d815309a655f25e13404dbed259ec8937465e |
| Sha512 | cde5d5bd37c6d1097a5d401871fa18ade5b33c2d986765407dd2f4895d4dc9d5b0d4afc02ec1340d3f646bd6892f6c7e4cc2d717bb2258e565ce552b83806aa0 |
| SSDeep | 49152:pDXrwW+/stv7JInHg9lWRzHyWwT39s5RnVJESQHMc132SMjlyoVFNXM3QR/396sS:pDbkmjKAapl22SMjlyKFeaZqg333iL |
| TLSH | 4D56AE03F389612ED06A2A37693B9694983F7A6039168C57DBEC3F4C8F791401D3A767 |
PeID
Borland Delphi 4.0Borland Delphi v3.0Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamRPolyCryptor V1.4.2 -> Vaska
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 4
STICH kept: 1secondary ignored: 3
bin
2img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>arc:7zsfx
Shape
pe:exe>arc:7zsfx
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x60A865 size 8680 bytes |