Suspicious
Suspect

2ed3e856b36863e1557090f09dc7317f

JavaScript
MD5: 2ed3e856b36863e1557090f09dc7317f
Size: 17.6 MB
application/javascript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2ed3e856b36863e1557090f09dc7317f
Sha1 6c473056de8b13360299f489b332e9bd70fb9c36
Sha256 5fe8e459e8cd447c472c9244bb8f092c5e3465ef072ca0bd50350c581fb267e3
Sha384 1d6e747094ec08511837b2e26c6ce6dfa0a8e260371baa4d9111272582e5371069be39a0da0200a66a07f8481261dcd1
Sha512 7ba263d599d0afbdacebfd8942299dc877e7495d4cc657929f247d8fe6c11b24d7fb2732917f10b735d4a1be7d6722ab168767c73172a9d0b78de11885ac5900
SSDeep 393216:J0L1F2pBgIfUKOc0XEAphVtnIwQSg+nFoIykzx8xvZ7X2r:CpspB58KP0RphDBo+FoIygx+vZ7
TLSH 7307339877854DA4F8FB423CA5C48E22A2B1B5242BA5D7BF0BF10D121D672D4DF387A1
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Overlay_82185c54.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe~T1059.007>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
technique3 nodes
Path pe:exe~T1059.007>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
technique3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_82185c54.bin (17254368 bytes)
Info
PDB Path: t$mn
Overlay_82185c54.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙