Suspicious
Suspect

d9bf7b1a5f8cb94f92ef00e67f7a285d

Share on LinkedIn
Print
PE Executable
MD5: d9bf7b1a5f8cb94f92ef00e67f7a285d
Size: 563.03 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d9bf7b1a5f8cb94f92ef00e67f7a285d
Sha1 dc1fe4117917b32c9a0e44cdc052fe444af95237
Sha256 a5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8
Sha384 0f80aa4201a070521568794b6a70b9ab2b3367a447dc05029a87129b7cc5c7f4a6942919d08542c6d0dd509ad1d289a9
Sha512 c62e42bdc4cae6bfa7b90ce3dcc577c03e6cef587e2ca9ea61f432f6bf6f20c53a8800b80c2d59398f132cc1e87680f5c5158e3010b82b50e5e73377804c028a
SSDeep 6144:4fL+oqmFRI0a6xsV9Rr7GbGB+OOQZj5X6j396SUT2BjGrs:4fL/FRBa6xsV9Rr7QGcfQN5X6b96qBjL
TLSH A8C41902303AF7A7D1D604B2248D74E91BB2EC65F9DA608911CF364C2BB1E158D9ED7E
PeID
Microsoft Visual C++ v6.0 DLL
[NSIS Installer] @ #0006C008
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
boreformnds.non
holostomate
sweetmaker.sch
[SETUP_DECOMPILED.NSI]
[Authenticode]_b1ee35dd.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x88E20 size 2360 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙