Malicious
Malicious

af1c0398b4ec4d2bed1496c63d0b01a9

PE Executable
MD5: af1c0398b4ec4d2bed1496c63d0b01a9
Size: 4.77 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 af1c0398b4ec4d2bed1496c63d0b01a9
Sha1 66adc37792d614d28fc1b4a26d5a4f5750e103e9
Sha256 3140e3c6570fb31aae5f424b2c6f81b7b91e654110bac5c562afdaced7e20848
Sha384 5efdc956ae493715fea563132c321a65feb368d8dcdd61b8966a6a05f833237605bc1f3c6b3311f4152748c9256877ec
Sha512 34d16edf6b07baf00197c0f0711a7f1df05bd47d524d611d0b6f606d818928d631ce0c09dd690f6e3f8532a786b259a42e294822fdec771c0057d81c6c64773f
SSDeep 49152:Sxmk6DiKfriJqVOTZauaKil8KgCInaoDP19fMuWBvJIPMxAmINGEDtxexicqouLi:IabWaYx7sgohT3higkVgohT3higk
TLSH AE265A22959113EDE17FC075898A5E13FB71700913616BEF09D045A3AEA7AF0AE7F342
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
HYPE_C2CFG
ID:0001
ID:1033
RT_RCDATA
ID:00D2
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
ID:00D3
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:rsrc>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
HYPE_C2CFG
ID:0001
ID:1033
RT_RCDATA
ID:00D2
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
ID:00D3
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙