Malicious
Malicious

208212a5b6e7c6f22107467066c44703

Share on LinkedIn
Print
PE Executable
MD5: 208212a5b6e7c6f22107467066c44703
Size: 4.75 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 208212a5b6e7c6f22107467066c44703
Sha1 b37cfbc8365861383ee9c499aaee6fb55a0d932a
Sha256 45155d8d55da2f7b1b6d23db7bab4bc54f1e8b49d32bfe5a3c66a0e1fe3fde35
Sha384 5fe645f798777f17420c6b39db698e8aeaf75268d0abdde6cc3d680f0cd4fe74d754596da10dd076876d9715446809ce
Sha512 5c959474280b097fe90b6e2c2835da96da58f3f5f1ea0138e7cca60758d3d09168795b9b0db9d111b2973ad542af4595ec179c89c76975e8d5cd1aa2f64ece99
SSDeep 98304:SbOLZZ/lUa0s7SCaqKSNhNEVJyZlng4p2Vu:SqZZ/lUFs7FtEVcn1pj
TLSH BD26D0447A00AA9ED44B8933C6EA0C18A7B0E8675757D307B87732BD990D7D7EE081E7
PeID
Borland Delphi 7 - Nstd EP - ASL sign Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_RCDATA
ID:0000
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.rdata
.data
.didat
Resources
RT_MANIFEST
ID:0001
ID:0
ID:1033
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
.Net Resources
{f4f5d655-d3f5-4ecf-9a53-3a2fe4afba9b}
RnsC:
Z0Az>S7ceT;H}HL:0Y$.resources
logoPictureBox.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
ls
p0l#ez"6 r wkmcf=YU"'%.resources
$this.Icon
[NBF]root.IconData
?18Z
,YcTt5!
+UrJh7sHJBcb9(.resources
{c61cd46d-9d75-437f-8270-5249854f931f}

{5a3e54c3-0556-4780-bd19-e692c4c55323}
J0pj1wKjhdmIPdLKrA65U.bat
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
IYd5qBcaFfYTOsqv9B.gDFvGWjjtjNHCR99FL
IbYmyfPPOeDgGC7mIU.gqyNWcErNV34v3Vn72
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
208212a5b6e7c6f22107467066c44703.decoded.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path pe:exe>pe:rsrc>pe:exe>scr:vbe>pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>pe:exe>scr:vbe>pe:exe>pe:rsrc>bin
malicious 7 nodes
Path pe:exe>pe:rsrc>pe:exe>scr:vbe>pe:exe>bin
Shape pe:exe>pe:rsrc>pe:exe>scr:vbe>pe:exe>bin
malicious 6 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙