Malicious
Malicious

4c67e21baee732cd8a98d35f3d5b4a0c

VBScript
MD5: 4c67e21baee732cd8a98d35f3d5b4a0c
Size: 7.53 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4c67e21baee732cd8a98d35f3d5b4a0c
Sha1 68533bf2160f132978fadaed049d9cb09571d913
Sha256 b3d5a1cc7eae4730a736b333b8a5b9092be7063bafbb637bc9977c6efd3e5312
Sha384 2f0967aafd49d6cc80cf537bb3b60ccdd4b3b78279da23689a2b6afe7b6c9c328fd40fa1f3b7eb8ae7584a8371e9ef76
Sha512 d5b4e245b418de66e2a33d1a0e37de291dad886ebad82801e83d3f1d3e779baf7cca6b9304d5e6b1ed3a381e564aaa325f710d7b396b583c52ba71bdc9c66f96
SSDeep 196608:cu11MftV2BNhzY01mQn1uJhAYBUxSVHjLkoM2HcaXhF:x1vThznL1urBB8on2EcaXb
TLSH DF7633C0CCBB1793AF5CD409E3B22A2A7F620D1916475D2D616E76362FE32E481276DC
App
Malicious
alpha59621
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Authenticode]_9be44668.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
RT_STRING
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
AppInfo
appicon_128.png
appicon_128.png-preview.png
appinfo.ini
appicon.ico
appicon_32.png
appicon_32.png-preview.png
Launcher
Installer.35-12-5-64.ini
splash.jpg
splash.jpg.exif
splash.jpg-preview.png
license.txt
appicon_16.png
appicon_16.png-preview.png
appicon_75.png
appicon_75.png-preview.png
appicon111.ico
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 1secondary ignored: 5
bin 3img 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
App
Malicious
alpha59621
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Authenticode]_9be44668.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
RT_STRING
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
AppInfo
appicon_128.png
appicon_128.png-preview.png
appinfo.ini
appicon.ico
appicon_32.png
appicon_32.png-preview.png
Launcher
Installer.35-12-5-64.ini
splash.jpg
splash.jpg.exif
splash.jpg-preview.png
license.txt
appicon_16.png
appicon_16.png-preview.png
appicon_75.png
appicon_75.png-preview.png
appicon111.ico
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
4c67e21baee732cd8a98d35f3d5b4a0c › Installer.35-12-5-64.exe
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
4c67e21baee732cd8a98d35f3d5b4a0c › App › alpha59621 › Installer-35-12-5-64.dll › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙