Malicious
PE Executable
MD5: c7b32f41601ff0cc571fd0d6008ac642
Size: 229.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | c7b32f41601ff0cc571fd0d6008ac642 |
| Sha1 | b5c7c4b3cc3dd7c9899d76e816921c9896175355 |
| Sha256 | 549eaa713063504459dafab521d4f536e34ae6c090f7bb52acb7e74364256aaa |
| Sha384 | c06bab64caad390d648c6cf1ef460c68366ff6aa532a450eb18a0f9a240755c652a8451ec8535dfe55778213a710f6d6 |
| Sha512 | df0ca4fbc2d25a047afa38d997af58c7a62ee6c51012b26b77e1c7b1a375988174bef6c90e11c3ba57eed5b7ed5a299898fc3a6d6a4cf984903fd642121e6927 |
| SSDeep | 3072:KRLiJRaxQRsgLY165GWp1icKAArDZz4N9GhbkrNEkO9qlTDdm3ppHqTJ:H3axQprp0yN90QEryipy |
| TLSH | F7248D0967E610A6F0B2677099F202834A39BC637B7592FF5780857D0E73AC4A971F63 |
PeID
Microsoft Visual C++ 8.0 (DLL)
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 2secondary ignored: 5
bin
4img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>scr:ps1~T1027~T1059.001
Shape
pe:exe>pe:rsrc>scr:ps1
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin>pe:dll>pe:dll
Shape
pe:exe>pe:rsrc>bin>pe:dll>pe:dll
5 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: wextract.pdb |
Deobfuscated PowerShell
UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential