Suspect
PE Executable
MD5: ac27ed9369c79339759263f46f1535e6
Size: 8.56 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ac27ed9369c79339759263f46f1535e6 |
| Sha1 | 0777914900b56dc42dfcbdaca092983d7be6077b |
| Sha256 | c55e5baca2162ac54e70de00a3d25b8a9a54617965eb36d1d7080f7d2e0460d7 |
| Sha384 | 8841bb68da39412e9c6fedc47e87e8fcc2e816685393817291b401cc2a49e5c9082f9c8f8b15a9f3386bea935c8b8efe |
| Sha512 | 40c08c6d7948fef5be07c43bead336721ce42517101d53dd0665aa7d76190e0b5f91586416544f068882bf05d032a53bbe212ce33726846c6dd886d9c0bfe629 |
| SSDeep | 196608:xChuBGmVGvizOtZg4xk5ipVxrLpfCYuVeXjXMrSoaQ:IQBrGGf4mehaVyM+PQ |
| TLSH | 878612263ED844ACD0DB94F455160507D2F9B012037B9BDFD6E109BB8FAAAF46E3A710 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 2
STICH kept: 1secondary ignored: 1
bin
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:exe
Shape
pe:exe>pe:exe
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
| Info | Authenticode present at 0x22DA00 size 10352 bytes |
| Info | Overlay extracted: Overlay_3fc96ce4.bin (6266268 bytes) |
| Info | Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_0e7b4166.exe |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential