Suspicious
Suspect

f6672017e794a57f2a49c95e4a66e32e

Share on LinkedIn
Print
PE Executable
MD5: f6672017e794a57f2a49c95e4a66e32e
Size: 869.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f6672017e794a57f2a49c95e4a66e32e
Sha1 5fafd3de8b172472b40b8eaa13a6d4415e7b6827
Sha256 e0e9e2fff6e00cfb9b3edb2fd50940fb573dd73be552a4b49042890ee33d92d0
Sha384 0916c5590dc749238a92cf54c43d69e54676f35c25e10f0ce37b1fe2dd20ae32822acbf33a6df385f6a27b7a8e06e72d
Sha512 a3840cfce1b8505cf518813d304b078eb94d0dccc2b6bacaa2ada0539e881bce6784a5a6da88ad361b290888fe28af06298bbed5ae8868c736853f5297709abb
SSDeep 12288:SyWZklYkVg8x+uoWNN7cJrZK6yLz6fQnDAQuUNdzMViWaJ8bfFJeoQ4JlaBHg2yM:SyWZgVotK/z0eAqrIeoQOlaX1
TLSH B5050246BF758606C7D493314CA542530F69EC466E70839F277CFF1A3BB21A3199A2B8
PeID
Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
[NSIS Installer] @ #0003A808
Sammenskrue
avaunt.ini
Strandvaskers82
bleachable.jpg
bleachable.jpg-preview.png
ekslibris.jpg
ekslibris.jpg-preview.png
nacelle.con
navere.ini
plantefibre.kon
premadness.ini
sardines.ini
sprogbrugs.txt
stoddere.ini
tricepses.txt
unleaderly.jpg
unleaderly.jpg-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
[Authenticode]_8ca7f367.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:dll
Shape pe:exe>pe:dll
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD39C0 size 2336 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙