Malicious
PE Executable
MD5: 2ca21f6f7c6568a9b8d9718bca568459
Size: 27.04 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 2ca21f6f7c6568a9b8d9718bca568459 |
| Sha1 | 159de83b66468938a989537d89687213c1c03973 |
| Sha256 | 36292969f0ed7d8a821006de3e995b68b8a7892b075ede7549267ade800afe45 |
| Sha384 | dd00b5d910f3c2dfc15820325bb26be307763977b4e14d37933bfadd827679b71e19ce13eae660f1f9b850a11ad3a1cb |
| Sha512 | 38e3fbe825835661b58a3b67adc7a57440c7a03049066889cf1ecdca6e3f3ece1581ad6302dee30201154aaa5f4780d21e03c96fbae960409949e275c2114286 |
| SSDeep | 786432:WHSH3erqNdZ08e5x2D1TLlcxzad0D/KWGcP0OL:1NP0l5kD1TL6xGuKWG0HL |
| TLSH | F2573370449E1F39F5292B3F6DBFB7198372BE01B5602426B276BDA4CE6B0728770845 |
PeID
UPolyX 0.3 -> delikon
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 4secondary ignored: 8
bin
7img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>arc:zip>scr:vbs~T1059.005
Shape
pe:exe>arc:zip>scr:vbs
technique3 nodes
Path
pe:exe>arc:zip>html
Shape
pe:exe>arc:zip>html
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_1bbcf3f8.bin (27002384 bytes) |
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential