Malicious
Malicious

ba5da443c5e881df3147e9c110240df3

Share on LinkedIn
Print
PE Executable
MD5: ba5da443c5e881df3147e9c110240df3
Size: 408.58 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ba5da443c5e881df3147e9c110240df3
Sha1 4841a82719a2ef2092752ccf107dcc021a59134c
Sha256 6c977cac10245be0d1222fa444aafeed327e840a8864c7a37feb401ed51e7257
Sha384 596880c7834025462b5c8464a195e01bd1a0d1e790c7b9c7b8c9a11741a9d3c4ee98bbfbc0173119449962395ca2f93f
Sha512 86d167aaa77b2ecf0b624e8c37b48073b98126aa05e9af949e362b5025f8a81210082810c169ea9a9a2987c3e8052e1110dd2a5f6b7c54e67161338e013e9c94
SSDeep 3072:VBRO3hCKpIdtHO1qeGAhY5dqkBfyboS0lYi5iNMfYT:nReIdtuE5dqkBfyboo
TLSH 4A9495273FB9DE48C21CBD7A69F18737B7318A250D4A05117E122E73D672DA8FB81684
PeID
Borland Delphi 7 - Nstd EP - ASL sign
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
Malicious
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_RCDATA
Malicious
ID:0000
Malicious
ID:0
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.Net Resources
Malicious
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:exe>scr:ps1~T1027~T1059.001~T1105
Shape pe:exe>pe:rsrc>pe:exe>scr:ps1
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙