Suspicious
Suspect

a117bee23d4586694cb4d41fe0f63d4d

Share on LinkedIn
Print
7Zip SFX Archive
MD5: a117bee23d4586694cb4d41fe0f63d4d
Size: 288.36 KB
application/octet-stream

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a117bee23d4586694cb4d41fe0f63d4d
Sha1 782d7593d55e62cd17c3c4f8e72986e103b0b240
Sha256 32f18c10963960a700766993ba755aaf2d407b542a2d8a2af3dbc8da7a2afab4
Sha384 26e41350fdbb74f39891bd91ce160ca5fa1fbe1d3d2af41c66f27791251992c521df21cb8e597fd27dcb8a99728c39e6
Sha512 73d38073a393c6e4f0d9fadf1a4a0d08dea2d58124291dd9a8ceda1233052cb87b0f4853f6534aaad05d5d04e1d4f2e386c00f38658b350713e644ccd2f6bc1a
SSDeep 6144:zLTHQOrRezFWuRwIDnJs3kjCUfMxromBDi8AVGFSfnYJDwPObu2C:zXwOrReFWQFjZqsmBerGsfYJDwG3C
TLSH E454F1033BC2C5F9E1D225324986B7B659FDF6240F298AC7ABC40E0B5A742D5D63D386
PeID
Microsoft Visual C++Microsoft Visual C++ 5.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
Overlay_ffb25f57.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:1049
ID:0002
ID:1049
ID:0003
ID:1049
ID:0004
ID:1049
RT_GROUP_CURSOR4
ID:0065
ID:1049
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Authenticode]_b9418c83.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
PNG
ID:006E
ID:2052
ID:2052-preview.png
ID:006F
ID:2052
ID:2052-preview.png
ID:0070
ID:2052
ID:2052-preview.png
ID:0073
ID:2052
ID:2052-preview.png
ID:0074
ID:2052
ID:2052-preview.png
RT_BITMAP
ID:006F
ID:2052
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_STRING
ID:0007
ID:1033
RT_RCDATA
ID:0360
ID:1033
RT_GROUP_CURSOR4
ID:0065
ID:1033
ID:006B
ID:1033
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.prcfg
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 2secondary ignored: 4
bin 3img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7z>pe:dll
Shape pe:exe>arc:7z>pe:dll
3 nodes
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_ffb25f57.bin (162406 bytes)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙