Suspicious
Suspect

551cab852dd5a71b69c8a1460e9e158e

Share on LinkedIn
Print
JavaScript
MD5: 551cab852dd5a71b69c8a1460e9e158e
Size: 17.59 MB
application/javascript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 551cab852dd5a71b69c8a1460e9e158e
Sha1 24e385fa40aae086b392a51f8a02cc06e7a8dec3
Sha256 311b06b21cba02b2c7f1a2e822a2bb86f2a8d691b801326e6dde7aec86bf0044
Sha384 1c7334bb4ed2ac8fd419ff03ff37d9ee0daffbbed3f7ccfad1210b697963435c8a8feff87a5cd03f2e917a66438053c9
Sha512 b19e2c2c816dacab4f7a99d538273a9f3a80dbe88fb8bfdfe2c730663e0f7546d24ab63b6f15603456f937f7e449724a0b9c70934d3f123d04d54da9d90b28db
SSDeep 393216:V0L1F2ugIfUKOc0XEAphVtnIwQSg+nFoIykzt8xvZ7X2:+psu58KP0RphDBo+FoIygt+vZ7
TLSH A607339877454EB4F8FB423CA9C08A22A2F1B5642B95D7AF0BF10E1219673D4DF347A1
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Overlay_db8122f1.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe~T1059.007>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
technique3 nodes
Path pe:exe~T1059.007>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
technique3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_db8122f1.bin (17238272 bytes)
Info
PDB Path: t$mn
An error has occurred. This application may no longer respond until reloaded. Reload 🗙