Malicious
Malicious

b0eac77c609e979069a74923fe5816de

VBScript
MD5: b0eac77c609e979069a74923fe5816de
Size: 12.08 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b0eac77c609e979069a74923fe5816de
Sha1 a36c2fcdb5895a8ab12f57409b855bb945f11112
Sha256 accbe9fca34638def5aa8a0c9d4cd7a536cc631c00a391d75e5a7b7548bade4b
Sha384 eb18d7e733ee9c88df7c75c97fde866090711554334389ab6b91acf258d516b1ae7ccf43a6045e10f9366747addf5898
Sha512 4e923d42b212b3ca5cbd31085cd8875612fb5774705f75976345b2b92c23bd48d6f986d0e69ae721f8eb6817ebe9bfdc081021e7c37cc3ca37f6b009f81fa409
SSDeep 98304:64EdCO388idcp7+hHL9XEYiUDeksd3p6ro26pHdOwd83r:64Ed3sTI7OL90YiUDhsK/6pHdL
TLSH E4C602059E5D5270CED64D76E1AA4B340F3A7711E310B4EBAF88828D46FF192D2E364E
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.rsrc
Resources
Malicious
RT_MENU
ID:00D3
ID:1033
RT_DIALOG
ID:00CD
ID:1033
ID:01F4
ID:1033
RT_ACCELERATOR
ID:00D4
ID:1033
RT_RCDATA
Malicious
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>scr:vbs~T1027~T1059.001>scr:ps1~T1059.001
Shape pe:exe>pe:rsrc>scr:vbs>scr:ps1
malicious 4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: t$di
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.rsrc
Resources
Malicious
RT_MENU
ID:00D3
ID:1033
RT_DIALOG
ID:00CD
ID:1033
ID:01F4
ID:1033
RT_ACCELERATOR
ID:00D4
ID:1033
RT_RCDATA
Malicious
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙