Malicious
Malicious

a74c2f34562da758b23a0697466847fc

AutoIt Compiled Script
MD5: a74c2f34562da758b23a0697466847fc
Size: 1.48 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a74c2f34562da758b23a0697466847fc
Sha1 bc3dd3a61bd69cd114e930198631fb11731ddbdf
Sha256 edc48d610c3410f12653b2e7ada4f66ed8cfc7bed556f215620b5ec747b6c1fc
Sha384 80e538b3e9a79d6f049b12108f8ca384fd5e6e25a1709e0400679d9809b965fb042bae00466a613dfa4ec41d2e9066cc
Sha512 f45df9fc2b77cee13170d5e182f171a4b218a1dd406d580d105a82a9c3522e0b1807ebb78a94fcadc23db4652f9a8422ce88b91fed43e04b2e972860d8d95bd9
SSDeep 24576:g4lavt0LkLL9IMixoEgearyEwoC/mA3zZ9iTSH8UzEA6/iCZvHNq9MmCS:Xkwkn9IMHea+EwxzSnUF6KGtaPCS
TLSH BA65DF1267DE92A5C3724173B966BB416E7FBD2505A1F19B2FD8093CFA60031821EB73
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
autB931.tmp.tok
Malicious
[Cleaned].au3
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:2057-preview.png
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 2secondary ignored: 2
bin 1img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:autoit
Shape pe:exe>pe:autoit
malicious 2 nodes
Path pe:exe>pe:rsrc>pe:autoit
Shape pe:exe>pe:rsrc>pe:autoit
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ????
autB931.tmp.tok
Malicious
[Cleaned].au3
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:2057-preview.png
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙