Suspect
VBScript
MD5: 326177e27aef5d34b2ae4d5c9935be62
Size: 14.31 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 326177e27aef5d34b2ae4d5c9935be62 |
| Sha1 | 0187cf883e634bb9c8069c1ccbe1323a055c4e65 |
| Sha256 | 8cd988e1f749a5e008128df6f2b7da55c2760fbcdf414f26260331db723e6a15 |
| Sha384 | 5353c214cba8324bc8f8ca55b2da0ed7a25f32eec2f239a39d1a7d38670bf57cad48efbfedfd83b4863275d7d3e8fcb8 |
| Sha512 | d7bc473b81b25c55e3b990a91568ea30fe37a511e7d27c1fdd69c76f31a53d02046e63fe4354e8125b65048f892e72ea8601b03d27d9157f5158846102520259 |
| SSDeep | 393216:jDWmx9Of0xB1PXMCHWUjXkcuI3/PGTAI:jD1OfCvPXMb8XxH/O7 |
| TLSH | D3E63308B6D502EDEDB3413DDDB088A5E63934A54BB2CACF1F4897A59C632E04D3E257 |
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>scr:vbs
Shape
pe:exe>scr:vbs
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_3b0a8268.bin (14013954 bytes) |
| Info | PDB Path: t$mn |