Malicious
Malicious

4c67e21baee732cd8a98d35f3d5b4a0c

Share on LinkedIn
Print
VBScript
MD5: 4c67e21baee732cd8a98d35f3d5b4a0c
Size: 7.53 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4c67e21baee732cd8a98d35f3d5b4a0c
Sha1 68533bf2160f132978fadaed049d9cb09571d913
Sha256 b3d5a1cc7eae4730a736b333b8a5b9092be7063bafbb637bc9977c6efd3e5312
Sha384 2f0967aafd49d6cc80cf537bb3b60ccdd4b3b78279da23689a2b6afe7b6c9c328fd40fa1f3b7eb8ae7584a8371e9ef76
Sha512 d5b4e245b418de66e2a33d1a0e37de291dad886ebad82801e83d3f1d3e779baf7cca6b9304d5e6b1ed3a381e564aaa325f710d7b396b583c52ba71bdc9c66f96
SSDeep 196608:cu11MftV2BNhzY01mQn1uJhAYBUxSVHjLkoM2HcaXhF:x1vThznL1urBB8on2EcaXb
TLSH DF7633C0CCBB1793AF5CD409E3B22A2A7F620D1916475D2D616E76362FE32E481276DC
App
Malicious
alpha59621
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Authenticode]_9be44668.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
RT_STRING
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
AppInfo
appicon_128.png
appicon_128.png-preview.png
appinfo.ini
appicon.ico
appicon_32.png
appicon_32.png-preview.png
Launcher
Installer.35-12-5-64.ini
splash.jpg
splash.jpg.exif
splash.jpg-preview.png
license.txt
appicon_16.png
appicon_16.png-preview.png
appicon_75.png
appicon_75.png-preview.png
appicon111.ico
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 1secondary ignored: 5
bin 3img 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙