Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9d56be0a712cfcf3dd4338156269acb0
Sha1 6d64daac659498745b7f76ff7f1d09e80e0eafef
Sha256 83c94b0406576b73e86d3c086f386986f8a95e0a5dab90c3e0a4bf4cf95e7327
Sha384 eea4351c509a8c4134246cc461ea3c51743b6065a7a4681a433b38f6c7a3b55a4a1514a3bd5fbec744e4d79e52ec0925
Sha512 37c971c16a24e234c88b940eacf1312d7552d546c54a09a27a094834f7ebc7eb79f1a689c99a319ec453f63a07264ee207a7a848b0641f0fc52ae8788aeae912
SSDeep 98304:zClvSIQotY1jJ6I/EQ+LxsE3WajDxlaEO:OlvSIQDbcQ+LxzmaJlHO
TLSH 2257294AFFD1CF42E9A6867898775B103373E8A54B71C3C7125461382D973C88EF2A99
PeID
HQR data fileMicrosoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_17131f37.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 2secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Path pe:exe>enc:b64
Shape pe:exe>enc:b64
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x1C25000 size 10704 bytes
Info
PDB Path: K&>.yC?B
)>O 'L>[??.xJ>Hf?y\PD>!?M???L>??|b=})>???\? >?v?c [1>H'????)>????dL?>Z?|??F>??N?i?;>??_??j+>??y??C>?O@?L?)>??uzKs@>??D>?H??e?@>?5?A?3>N;kU??r=C?A	? >???	p?.>E???K>V???R?>>?e?
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_17131f37.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙