Malicious
Malicious

22572deb99904d6257b6326e4fcf0d3c

Share on LinkedIn
Print
AutoIt Compiled Script
MD5: 22572deb99904d6257b6326e4fcf0d3c
Size: 1.48 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 22572deb99904d6257b6326e4fcf0d3c
Sha1 6137850f5164e98e16cbe48abafe86114102bc27
Sha256 cdcf6356e2b101544a660c16e672ec81a0be2523f5bbee9abc36ae47ec93c8ea
Sha384 51e0cfcbfe9cdc63e4a5ae94a62a21d828a26a8a897b47dd57d7b4a829c57d06ad87ca1c165ccb44ff173550b7732f8e
Sha512 45aaf2287761a6a3bf1943268ac7367fcaf04f319ff4dbb31ebaf03e3881f551c5294926993028bc75b8134b03e4f38d935c7576a15d59223176c7dc6314dbdf
SSDeep 24576:826z5Ayhmpibv+RM3sODXlTucSw0RDPqKYuieywnzL0t++DPsEUxNzh0yktvBZ7:m1Ayhsib6eRtuY0wKYDVwzs+ePsEUXSf
TLSH 4C6523D193E184E9D1F5273088F3855B2572BC26977F46CF23442A4E1B23AD29A7E34B
PeID
Microsoft Visual C++ 8.0 (DLL)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
aut5105.tmp.tok
Malicious
[Cleaned].au3
Malicious
[Authenticode]_39db20af.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
ID:2057-preview.png
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:000D
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_DIALOG
ID:03E8
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:2057
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 4img 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:autoit>pe:autoit
Shape pe:exe>pe:autoit>pe:autoit
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: wextract.pdb
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙