Malicious
PE Executable
MD5: d24014049064389357dab970e72e6298
Size: 4.64 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | d24014049064389357dab970e72e6298 |
| Sha1 | 210a5380007df4fa49140410938a39f2251d6548 |
| Sha256 | f535cdbb32dd25fa7dfbcdbae96eafbd5740882e46355c78c895224de6f22e4e |
| Sha384 | 4e2703b74b35e8c82f9c399278a8db911f00855616e07306f4003bcc901b11ee97d4005b2988b68d13f3a1f3c94d83e6 |
| Sha512 | 53ebeeb2faafa2a8c7331cc9d10f1a2772f3ca6e18f77b64725e6099598b4614841c233fab2886407cc6bdc254e40e614df7b5a3970cc0dd24eb26a39b53d1f1 |
| SSDeep | 98304:+AYSNdx/hBiTCL3S+IkhRTWEqfn0FJEehp+8:+AYSNdx/Gp+IGZW9f0FJEehp+8 |
| TLSH | C026BF56D1A943D8E473157895109AF05BE66CAEF1E4B402BDBCB42F4FB79C0C92A0B3 |
PeID
MSVC++ v.8 (procedure 1 recognized - h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
6 / 6
Path
pe:exe~T1059.007>pe:rsrc>img>img
Shape
pe:exe>pe:rsrc>img>img
technique4 nodes
Path
pe:exe~T1059.007>pe:exe~T1059.007>bin
Shape
pe:exe>pe:exe>bin
technique3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_ac49aa41.bin (2797320 bytes) |