Suspicious
Suspect

a6482ea44033007a9da963cd3ff5ce49

Share on LinkedIn
Print
PE Executable
MD5: a6482ea44033007a9da963cd3ff5ce49
Size: 440.22 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a6482ea44033007a9da963cd3ff5ce49
Sha1 2430d4d428b8f4a4f63b3f62d917ae49afeed37a
Sha256 f12c120af203e20c35f019ff8eefc52a3cc5fae18b4a55e9a8c835d6ee88f098
Sha384 804c7a975d48d170f7233c15e45a68effc5a8f846ef23ae442a56f47e05078fe6cd81d22fd9364bb4396ce25632a9a40
Sha512 915d67c243dc94489c184189fcf6416317675007459994507f06d8d67a26bea9c63a75bc7a8a21cc7788568c06f9cdcc4dd98fb263e601201fb6ce39cf88451f
SSDeep 6144:mTA8oPSCIjqP6r93+tF5yglzXLvX1YO6hsKYnu+jVig:mTA6eowv1lzXLvX1f6iKAx
TLSH 2994BF13F654C986D81022F04C7FD8292263AD7899A3560F3DADF73D9EB3292F11764A
PeID
Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #00031808
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Riddervises
anettas.txt
doktoreres.ini
unbuckled.ini
[SETUP_DECOMPILED.NSI]
[Authenticode]_dc28fc1d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_BITMAP
ID:006E
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
RT_DIALOG
ID:0068
ID:1033
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x6A480 size 4888 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙