Suspicious
Suspect

1e89cbba71b97dcb1900dc9c9a1ff6dd

VBScript
MD5: 1e89cbba71b97dcb1900dc9c9a1ff6dd
Size: 5.24 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1e89cbba71b97dcb1900dc9c9a1ff6dd
Sha1 ffd0967e5e31525f440bfe57f173a9de6ae8b123
Sha256 b8f6e07204c3154fc5ba0df22926a0c181db479e193dfab573714d004e4d4ed0
Sha384 fee3d4dc5cd32bc893e94b822928c09fdb2f9e3258629a537cc9dad49faea235adfb6f521f299f171f24e4c27cdf62b3
Sha512 977792e5a2431348d5dab6adba35bf5426bc9936e0a2619e7bacd1a55f6ae8e7a85c6039dc273807006b18ab39a341283596562e0f5c4546431c2197bc56abfc
SSDeep 98304:B/eJbNJUCr5KbUoEpG8xi/Xga5sExhUI7x3oxZ62zkExPspBntzbk8ZnVkz:I5/V7oBaiPpsyhLNYxb4ExkLBhn6
TLSH 723633AEF34C6153DCB09BB391DD1780951A6CF06C0AE10B627CFB3326B5661FA994B4
Root Entry
䡀䌏䈯
[Authenticode]_7a5a4d33.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
mgnTvVqLcdTGxUZMEpD
[Authenticode]_80c5211b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
hn5XwpLUI2G8SBWD9
[Authenticode]_d5fe54cb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_0d91449b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_e457b1eb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
hpZRQBBciwJzT
dyvsokXXKFRz03yW8Arm
mgnTvVqLcdTGxUZMEpD
hn5XwpLUI2G8SBWD9
DEWTud3JSrCytqK
Oj7QkJVzat8
hG3vvZDdOfpOjoWGpiXU
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 6

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:vbs>pe:dll
Shape ole:doc>scr:vbs>pe:dll
3 nodes
Root Entry
䡀䌏䈯
[Authenticode]_7a5a4d33.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
mgnTvVqLcdTGxUZMEpD
[Authenticode]_80c5211b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
hn5XwpLUI2G8SBWD9
[Authenticode]_d5fe54cb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_0d91449b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_e457b1eb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
hpZRQBBciwJzT
dyvsokXXKFRz03yW8Arm
mgnTvVqLcdTGxUZMEpD
hn5XwpLUI2G8SBWD9
DEWTud3JSrCytqK
Oj7QkJVzat8
hG3vvZDdOfpOjoWGpiXU
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙