Malicious
Malicious

ba5da443c5e881df3147e9c110240df3

PE Executable
MD5: ba5da443c5e881df3147e9c110240df3
Size: 408.58 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ba5da443c5e881df3147e9c110240df3
Sha1 4841a82719a2ef2092752ccf107dcc021a59134c
Sha256 6c977cac10245be0d1222fa444aafeed327e840a8864c7a37feb401ed51e7257
Sha384 596880c7834025462b5c8464a195e01bd1a0d1e790c7b9c7b8c9a11741a9d3c4ee98bbfbc0173119449962395ca2f93f
Sha512 86d167aaa77b2ecf0b624e8c37b48073b98126aa05e9af949e362b5025f8a81210082810c169ea9a9a2987c3e8052e1110dd2a5f6b7c54e67161338e013e9c94
SSDeep 3072:VBRO3hCKpIdtHO1qeGAhY5dqkBfyboS0lYi5iNMfYT:nReIdtuE5dqkBfyboo
TLSH 4A9495273FB9DE48C21CBD7A69F18737B7318A250D4A05117E122E73D672DA8FB81684
PeID
Borland Delphi 7 - Nstd EP - ASL sign
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
Malicious
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_RCDATA
Malicious
ID:0000
Malicious
ID:0
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.Net Resources
Malicious
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:exe>scr:ps1~T1027~T1059.001~T1105
Shape pe:exe>pe:rsrc>pe:exe>scr:ps1
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
Malicious
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_RCDATA
Malicious
ID:0000
Malicious
ID:0
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.Net Resources
Malicious
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
ba5da443c5e881df3147e9c110240df3 › Resources › RT_RCDATA › ID:0000 › ID:0 › .Net Resources › script.ps1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙