Malicious
AutoIt Compiled Script
MD5: 301e927cd4b68262f1c3f8f29f2c4586
Size: 20.39 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 301e927cd4b68262f1c3f8f29f2c4586 |
| Sha1 | d5f1d65724042f5c6e86c6309418efc041d3e1ab |
| Sha256 | 696329a31289fd29b81a5fcaeedec83bea3cd21aa9a721ae50650a6a1ac6c00e |
| Sha384 | 70c731531edd28714f77066aa6b68573f4461f64d688fdaa3356084e5f22f3a5a6e69e63d7f0a5097e69dba561ae4478 |
| Sha512 | ead26c8a37985bb84308f1d6dfa404329d7fd54a184239501ed79b9a6e3fd7c56b9d903d04eb30c4adbd26525485964d78511f555983024e444a19c0dd5c312a |
| SSDeep | 98304:d7BcFS5aiA65GTK3/cAjp/hdePFPZxjIJrM0ZdgGoG2cPK85gBvlAdL:7cFSIAj9hgYJ40ZdeCKs6adL |
| TLSH | 4227824E36028017EDA62737C5F28252AC77AD304719C4DE35907E9A5E78EDF093D3AA |
PeID
Borland Delphi 2006Borland Delphi 4.0Borland Delphi v3.0Borland Delphi v3.0Borland Delphi v3.0 - v7.0Borland Delphi v6.0 - v7.0Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLMicrosoft WAV Audio filePe123 v2006.4.4-4.12RPolyCryptor V1.4.2 -> Vaska
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 5
STICH kept: 2secondary ignored: 3
bin
2img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:dll>pe:autoit
Shape
pe:dll>pe:autoit
malicious
2 nodes
Path
pe:dll>pe:rsrc>pe:exe>pe:rsrc>pe:autoit
Shape
pe:dll>pe:rsrc>pe:exe>pe:rsrc>pe:autoit
5 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |