Malicious
7Zip SFX Archive
MD5: 94e791c4f0e69665c326c0ec634aa0b6
Size: 6.55 MB
application/octet-stream
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 94e791c4f0e69665c326c0ec634aa0b6 |
| Sha1 | a8e2d79ce69eba035dc87ee8730c3d926bcf070a |
| Sha256 | a3fcd1222767342c0d8962b8828fca4e65424ad76c05fe3144885629397a521c |
| Sha384 | aaec274972de24c62bb7e3e1e299bc00def3161564aa575c05c6e897abcce73484b7faae3f8ed4538c2dabc43cf5a1eb |
| Sha512 | a2ea4d0ea9d58d9d2c5eb1af275b097b7374b105a5b3377178c4d44e0126eaaaff2d6a28ab3ce943f9db787a36744134f1902c004b12ef2a715c0de75d40e14d |
| SSDeep | 98304:Snsmtk2aYeD21u2seJKLcxndGaX6tJJQv2FKA75OpVclc02vDRZTEw:cLcD21u2segLoo3u0jc02vVZow |
| TLSH | 2C6612337E55E03BD0221A3A9C9772D40A2BBE119D362C4A26E71E4F0B26DF7593D193 |
PeID
BobSoft Mini Delphi -> BoB / BobSoftBorland Delphi 4.0Borland Delphi v3.0Borland Delphi v6.0 - v7.0Borland Delphi v6.0 - v7.0D1S1G v1.1 beta --> D1ND1S1G v1.1 beta --> D1NMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 16
STICH kept: 11secondary ignored: 5
bin
4img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
11 / 11
Path
pe:exe>pe:rsrc>oox:xlsm~T1027~T1059.005~T1112>oox:vba~T1027~T1059.005~T1112
Shape
pe:exe>pe:rsrc>oox:xlsm>oox:vba
malicious
4 nodes
Path
pe:exe>pe:rsrc>oox:xlsm~T1027~T1059.005~T1112>oox:vba~T1059.005
Shape
pe:exe>pe:rsrc>oox:xlsm>oox:vba
malicious
4 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential