Malicious
Malicious

f4919af8d32d5683d0b25a725d811ba3

Share on LinkedIn
Print
PE Executable
MD5: f4919af8d32d5683d0b25a725d811ba3
Size: 790.53 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f4919af8d32d5683d0b25a725d811ba3
Sha1 60284ac2c4aa744d121af4643b848ec28c26c697
Sha256 5a8ae0c43eada84b75da50c8f2da0d9db494b5c38d9f527d8872510632cc2cea
Sha384 043443475f5ad83d99cf522d7cd7aa522807e7d6fff26518ebd9fa62ea53415d313503c343d0a696538336adfb521ed7
Sha512 0e45b77c63f405af3712f64e1cfd0f4215c9c600444e82dc3a13da8a15ca3e579612e0a0d20babef582be252831904efb0d152ee9a85e4001fea4b0c419c323c
SSDeep 12288:usy90M1h6pFf2iMc2UtsBd1wO2QjFF/s6oW/kBwb4DcUhYwcNV866VDLfjoA/:rylEpbMc2Ut+FFRbqVhYwcf8hLfEA/
TLSH C0F4020567F961A6E5B6573069B202974A327CA25B39C3DF12D4C67E1F33BC0A934B23
PeID
Microsoft Visual C++ 8.0 (DLL)
Install-InboxAI.ps1
Malicious
[PowerShell Command]
Malicious
Install-InboxAI-Worker.ps1
server.mjs
icons
icon-16.png
icon-16.png-preview.png
icon-32.png
icon-32.png-preview.png
icon-48.png
icon-48.png-preview.png
interface
content.css
popup.css
vendor
LICENSE.mammoth.txt
LICENSE.pdfjs.txt
mammoth.browser.min.js
pdf.min.js
0x00011C79.svg
0x00011C79.svg-preview.jpg
0x0003DAD0.svg
pdf.worker.min.js
manifest.json
background.js
content.js
0x00004043.svg
0x00004043.svg-preview.jpg
THIRD_PARTY_NOTICES.md
icon-128.png
icon-128.png-preview.png
locale-language.json
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:2070
ID:07D2
ID:1033
ID:2070
ID:07D3
ID:1033
ID:2070
ID:07D4
ID:1033
ID:2070
ID:07D5
ID:1033
ID:2070
ID:07D6
ID:1033
ID:2070
RT_STRING
ID:003F
ID:1033
ID:2070
ID:004C
ID:1033
ID:2070
ID:004D
ID:1033
ID:2070
ID:0050
ID:1033
ID:2070
ID:0053
ID:1033
ID:2070
ID:0055
ID:1033
ID:2070
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2070
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 12 STICH kept: 5secondary ignored: 7
img 4bin 3

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>scr:ps1~T1027~T1059~T1059.005>scr:vbs~T1059.005
Shape pe:exe>scr:ps1>scr:vbs
malicious 3 nodes
Path pe:exe>arc:zip>scr:js~T1059.007>img
Shape pe:exe>arc:zip>scr:js>img
technique4 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: wextract.pdb
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙