Malicious
PE Executable
MD5: ff398178642634364b05ae413091f831
Size: 253.48 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ff398178642634364b05ae413091f831 |
| Sha1 | f515654bd03bc3c0636ab9334cc98b14ea81a19c |
| Sha256 | 1f8604584b410ae9b6037d2975d01093832d6b63d454c4b9f40c8f3d1c8b89d5 |
| Sha384 | 91bd780fb88553199eb0b912bb3e50f918fbd2d458063aee397568c7c17e441df47f45273b3c844529eb49f6cfe87b9f |
| Sha512 | b2cf52eb55662d37e223dae06f3304cf6d446ca59f43523a458c3a11d990e209084796af72dbbd3d06576f97c8502db6a938d6b5b22839053a15d0dec60992e7 |
| SSDeep | 6144:sBuaWausszGyeOeB/1hGFaUVDtGk3GVOvk4:YuaWausszMhhADum |
| TLSH | 214493D37654EA3DD1556AB248FE0C60EB7AA4E2D333A5374FC56A3009E130D5C2AB2D |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
| Info | Overlay extracted: Overlay_002d5910.bin (39 bytes) |
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential