Suspect
e097be87d39d5673afd233fbb535d768
VBScript
MD5: e097be87d39d5673afd233fbb535d768
Size: 14.32 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | e097be87d39d5673afd233fbb535d768 |
| Sha1 | 4920e8b0a9e9975aa3f032dc234937b053738114 |
| Sha256 | fe33733d353438f4edcf5baf73b602a3a668cc5a948e4a685b13d5d4bfc16b12 |
| Sha384 | 89392a7de007ab73f2787c5b9f9ee551c4d980360e2b904be04ce5cf43d06b76aac27da95a134909d0e52fdab4256f77 |
| Sha512 | b8270b6584087283ef62dd6459cd0eaa2a0688ef37ae8ef5b2febce61bd3fb6db2e1d04e6e978a12c3a6974ed81e9904cbc0a19c89b7d1b2724adb69aa1404c5 |
| SSDeep | 393216:GgtTYVvhwkt1E7PnFgaLmohSkZm9XMCHWUjXicuI3/PGTAI:GgiVv7t1YPnJKoG9XMb8XfH/O7 |
| TLSH | D9E63359A9E000FFC8B3847DE9E15695E5B1B4BA47B2C9CB5A34C2763D032E1493A733 |
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>scr:vbs
Shape
pe:exe>scr:vbs
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_dca25948.bin (14020842 bytes) |
| Info | PDB Path: t$mn |
No malware configuration was found at this point.
You must be signed in to view YARA rules.