Suspicious
Suspect

caf7d5d928b90f08384795d8552f0df3

Share on LinkedIn
Print
PE Executable
MD5: caf7d5d928b90f08384795d8552f0df3
Size: 14.32 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 caf7d5d928b90f08384795d8552f0df3
Sha1 69c404e697583f45a47e8a1b098e80e047e090b3
Sha256 fdb636d63b316929768ebe2c2ebf6b0a9eae33a18fef4426efdc62d13712f28f
Sha384 766f2bac720610abb4036abf7bab4868b2b55376926d38bf3cedb042067c72b664d7fb8b8ec8c1cf624d456577cbf189
Sha512 d1012c46b8a622e680889b59f148d026d8f428cf3c88e81a60e8a667d85b3675ae39d9a8591bb66fae44cce37f51b10256464cd8494c2e4883c1c67b262c567e
SSDeep 393216:zh/cCwAq1KPr2LzAT2GdgVXMCHWUjXxcuI3/PGTAI:zh/cXoyLs2AgVXMb8XmH/O7
TLSH 63E6330DA6C112FDE1A7843CEB535219E2B2B4B70772CE9796E8C3895D5B2A1CC3C613
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Overlay_93798f88.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_93798f88.bin (14024161 bytes)
Info
PDB Path: t$mn
An error has occurred. This application may no longer respond until reloaded. Reload 🗙