Suspect
b3c9d1993a05188c4bce23a34aa1d549
VBScript
MD5: b3c9d1993a05188c4bce23a34aa1d549
Size: 21.36 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b3c9d1993a05188c4bce23a34aa1d549 |
| Sha1 | e71485853edf523fe5a5fb1d6e3b543b65feb652 |
| Sha256 | 8bf367564afbbc28d3101d21124b5bfc3ec006fb32d4a2ba3fb9ccf1414fad8b |
| Sha384 | ae2bfe6ae440ccfa13ac291e2bcb5345c1ba7e6a6c337d7e005745a8c695a067e84bf3efa6c607b1ff6e882cb0ce4e3f |
| Sha512 | 4ac1c774577a5182a06b04ca580f5c0992de08f0e4678ed43890ab171cb321882d6414c44df38da07d9f793e773eccf81c9452acc2dc7b0581be14bf43712087 |
| SSDeep | 393216:mCyLpUDY1B6aZsxSzbNbgbRi1mrZeaACA8Mf0SiNJzgbWA:MGD4NIoA414enP40iA |
| TLSH | 10271223F38D653FD05B3E3D663792A4987B76602D128C57A6FC2A8C4F391801E2A757 |
PeID
Borland Delphi 4.0Borland Delphi v3.0Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12RPolyCryptor V1.4.2 -> Vaska
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 5
STICH kept: 1secondary ignored: 4
bin
3img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>arc:7zsfx
Shape
pe:exe>arc:7zsfx
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_78905260.bin (17871708 bytes) |
No malware configuration was found at this point.
You must be signed in to view YARA rules.