Malicious
d3cea61538aa5030e90a1d38cca762b4
PE Executable
MD5: d3cea61538aa5030e90a1d38cca762b4
Size: 1.86 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | d3cea61538aa5030e90a1d38cca762b4 |
| Sha1 | dd39fafbdba994169991cea092c6428e1d3b1539 |
| Sha256 | 594033ed58e27b42bb1bef7e5b21eac87f0d660c7cc3d48881a2e5575e3ac811 |
| Sha384 | f0cb8809fe6e2485b1668eea53fb27df3dbcab53a964d8b42731e7ce16f0e6c01981d5aeda6ab9183186e1a292efe214 |
| Sha512 | 9672ce4ba4bef67039cbd5274a7e3e6010261d961b5eb2c45df254397b567923d72c40130ec7524cb15fcc6d32b5a50908f870329568c6830fe10916144f9af3 |
| SSDeep | 49152:pJ1O7EpfelenkVglN5suzIEUP7ZmQNRBDXG+Chg9GPcPIvGqgu/2JZfy:pSVqkVglN5ye+m9cPW |
| TLSH | A4857D71279BC43AC57E80B02529FDBF943D5D269F5598C3A3D87D1E29384C21B32B2A |
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamVC8 -> Microsoft Corporation
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 4
STICH kept: 1secondary ignored: 3
bin
2img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>scr:ps1~T1027~T1059.001
Shape
pe:exe>pe:rsrc>scr:ps1
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x1C2E00 size 10704 bytes |
| Info | PDB Path: C:\ReleaseAI\win\Release\stubs\x86\Updater.pdb |
Deobfuscated PowerShell
UNKNWOWNmalicious
[Windohuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell
UNKNWOWNmalicious
[Windohuhuhuhuhuhuhuhuhuhuhu
d3cea61538aa5030e90a1d38cca762b4 › Resources › RT_RCDATA › ID:00F1 › ID:1033
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.