Suspicious
Suspect

d9bf7b1a5f8cb94f92ef00e67f7a285d

PE Executable
MD5: d9bf7b1a5f8cb94f92ef00e67f7a285d
Size: 563.03 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d9bf7b1a5f8cb94f92ef00e67f7a285d
Sha1 dc1fe4117917b32c9a0e44cdc052fe444af95237
Sha256 a5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8
Sha384 0f80aa4201a070521568794b6a70b9ab2b3367a447dc05029a87129b7cc5c7f4a6942919d08542c6d0dd509ad1d289a9
Sha512 c62e42bdc4cae6bfa7b90ce3dcc577c03e6cef587e2ca9ea61f432f6bf6f20c53a8800b80c2d59398f132cc1e87680f5c5158e3010b82b50e5e73377804c028a
SSDeep 6144:4fL+oqmFRI0a6xsV9Rr7GbGB+OOQZj5X6j396SUT2BjGrs:4fL/FRBa6xsV9Rr7QGcfQN5X6b96qBjL
TLSH A8C41902303AF7A7D1D604B2248D74E91BB2EC65F9DA608911CF364C2BB1E158D9ED7E
PeID
Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #0006C008
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
boreformnds.non
holostomate
sweetmaker.sch
[SETUP_DECOMPILED.NSI]
[Authenticode]_b1ee35dd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x88E20 size 2360 bytes
[NSIS Installer] @ #0006C008
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
boreformnds.non
holostomate
sweetmaker.sch
[SETUP_DECOMPILED.NSI]
[Authenticode]_b1ee35dd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙