Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f4cb26da786b7dcf513ef3386086b566
Sha1 a8e7d17e74a1b0c8cfe3b5fa7769c10eb133d83a
Sha256 c4057d8222ea5eef7529ea1c01727b939443a6501dcb18504ff8097b5ce476eb
Sha384 00bb44941e5516648403b66a6d5b2b7dad68db47343fbca722022456adaaaef096dc43c008893d1b1a2d2a4d6456df85
Sha512 7a2bf082df1f62918f3fd7590fde75d3fcf081cd620bfce5fef60b5976fbdfbfd460f6e1ec5e96f90a28794b9f15a656a351feb641740f866cb530ec3e2307ea
SSDeep 98304:9ClvSIQotY1jJ6I/EQ+LxsE3WajDxlaEY:MlvSIQDbcQ+LxzmaJlHY
TLSH 5257294AFFD1CF42E9A6867898775B103373E8A54B71C3C7125461382D973C88EF2A99
PeID
HQR data fileMicrosoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_24f589a2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 2secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>arc:7zsfx
Shape pe:exe>arc:7zsfx
2 nodes
Path pe:exe>enc:b64
Shape pe:exe>enc:b64
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x1C25000 size 10704 bytes
Info
PDB Path: K&>.yC?B
)>O 'L>[??.xJ>Hf?y\PD>!?M???L>??|b=})>???\? >?v?c [1>H'????)>????dL?>Z?|??F>??N?i?;>??_??j+>??y??C>?O@?L?)>??uzKs@>??D>?H??e?@>?5?A?3>N;kU??r=C?A	? >???	p?.>E???K>V???R?>>?e?
1.435.743.0_to_1.435.750.0_mpasdlta.vdm._p
1.435.743.0_to_1.435.750.0_mpavdlta.vdm._p
[Authenticode]_24f589a2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
BINARY
ID:0000
ID:0
CABINET
RT_VERSION
ID:0001
ID:1033
[Base64-Block@0x0143BEFC]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙