Malicious
PE Executable
MD5: 19f88273e1076a090e4ec439c2ee560c
Size: 4.4 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 19f88273e1076a090e4ec439c2ee560c |
| Sha1 | 6fe767347543cf94386c17d98306ffd2798b2438 |
| Sha256 | fe892c48559945e7e707a5fed5324ad5c2588de0965152c0ecd8b6e6b07e56d6 |
| Sha384 | e05f75d89d4438818d62675dfe433b89a5b16d754ec151b10a6dc665f77a22b9116386e7c2941a8bcc5828ac10c757a2 |
| Sha512 | 99fe74f4d23f122e54bf44b0f989910506215fa623baf03df9453f7e676c562b9808ba0404d73b6b78aa757d227c9ddc22cb35167511ea797f65aaf3fd83ab4a |
| SSDeep | 98304:jnsmtk2aaAD1e6OE6wDSUIEgzD/NrS27fgAf1HKcU/Y/:7LhADzOEpSUhglu27oAf5t |
| TLSH | 18161222B2D18437D1322A3C9C6BA3A5583EBE513D38764E7BE91D4C8F396423D652D3 |
PeID
BobSoft Mini Delphi -> BoB / BobSoftBorland Delphi 4.0Borland Delphi v3.0Borland Delphi v6.0 - v7.0Borland Delphi v6.0 - v7.0D1S1G v1.1 beta --> D1ND1S1G v1.1 beta --> D1NMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John ReiserUPX v2.0 -> Markus, Laszlo & ReiserUPolyX 0.3 -> delikon
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 24
STICH kept: 12secondary ignored: 12
bin
9img
3Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
12 / 12
Path
pe:exe>pe:rsrc>oox:xlsm~T1027~T1059.005~T1112>oox:vba~T1027~T1059.005~T1112
Shape
pe:exe>pe:rsrc>oox:xlsm>oox:vba
malicious
4 nodes
Path
pe:exe>pe:rsrc>oox:xlsm~T1027~T1059.005~T1112>oox:vba~T1059.005
Shape
pe:exe>pe:rsrc>oox:xlsm>oox:vba
malicious
4 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential