Suspect
VBScript
MD5: 4cab81b8fa6b59e3b06b3aba29204a21
Size: 14.04 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4cab81b8fa6b59e3b06b3aba29204a21 |
| Sha1 | a2d100f8c337b073b53f0b34c4b1c22581476178 |
| Sha256 | 2dfe533cdd6c2ea50640338fd3a53ffb5620e82009575bd27aa10be5e7444897 |
| Sha384 | 50c51444d85d47de088748bc632eb3e3188cd1d01b588acec18b611dcce863d78776fbf8ab3395742b2f992b2d260286 |
| Sha512 | b6af389d9171cffc946cae8f5cceb80973f1b1357d0b38cef42b77abab6682a06173741bec70dfa6df78ce7c7d3b6e391853d064bbdb11e0600fe31d304c3382 |
| SSDeep | 393216:Y2pLhljlQs3N45EVgb8EH0bPXMCHWUjWcuI3/PGTAI:YOnlj3N43bVH0DXMb8rH/O7 |
| TLSH | F9E6330CBAE411FED973C03CD9E21592EAB8B9351B36C1DB47E447229E571F08938A67 |
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>scr:vbs
Shape
pe:exe>scr:vbs
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_f91adef0.bin (13737537 bytes) |
| Info | PDB Path: t$mn |