Suspect
b01bcc20137e6cc6683881d70eef7815
VBScript
MD5: b01bcc20137e6cc6683881d70eef7815
Size: 14.31 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b01bcc20137e6cc6683881d70eef7815 |
| Sha1 | 0a75d1cfd95172aa20d75a4fbc67952b8aca1ac2 |
| Sha256 | 88a809fd0fbcfe06987d6c3ec704c78f0c5a1d83aee1ce8b54954d6a6a9d6f87 |
| Sha384 | 631efd2bb282922ee3bce3d8b8793925f74f6039a9bbbb43d5506621b8614fc060ebd6a88c4a3904bc14d6d6ae3a801c |
| Sha512 | 8c3275fb590efef55e29131db168e48562e24dbb603b648cfad695b7bedd1ee1dbaf27365ac0e20fd52139d3048539d8aaf4174174db6cee3794079d33449a80 |
| SSDeep | 393216:6dzs3wbzzulfPvPZFmXMCHWUjXecuI3/PGTAI:6dYgbzz83vKXMb8XTH/O7 |
| TLSH | 38E6336C6BE012EBEAE7513CED932691D0B4B4671372CD9B1BE883A52E171D14E3D213 |
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>scr:vbs
Shape
pe:exe>scr:vbs
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_2778b089.bin (14015545 bytes) |
| Info | PDB Path: t$mn |
No malware configuration was found at this point.
You must be signed in to view YARA rules.