Suspicious
Suspect

be417722cd7ae8d2b049cef6bb7dd32d

VBScript
MD5: be417722cd7ae8d2b049cef6bb7dd32d
Size: 2.98 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 be417722cd7ae8d2b049cef6bb7dd32d
Sha1 1aab2e355e9ea305db8270930c7c2e764d7e3b56
Sha256 c9ffc5922f06b518cef5f5dae98914b112de01fdc4ddfd6c7d69a5bd5dbe6ab0
Sha384 cacc3c3976566c30d8e01d8606219749dc31822c27a3b11ed3f94937fa3f80e71aa44fd2fd9242ca700659b012e76c87
Sha512 dec50f26cfaf54945e365609037862ed27d67729d6bf1eacb38aaeb7aa86e12adb11cfb2da55d29f83a05f6b520c3568539fb85d11dc17e4b28efba9a18f1b95
SSDeep 49152:yAPGhqQqCEF1b80OMai5wqVp4ZG8JRBm0OuZUDW5MygHC43xm0L/50GDhAFpIz:yAnQq1FJ8phIw3ZcAx5/gHl3BLnW
TLSH F4D523DAB8FA1DB1C472CBB29F82F47DB11D37854BA18EDA398D6A008D536182D35371
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.FOk
.B;:
.#)3
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.CRT
.FOk
.B;:
.#)3
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙