Suspect
VBScript
MD5: f64c86017ea3629c645c5695e4dd136b
Size: 14.34 MB
text/vbscript
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | f64c86017ea3629c645c5695e4dd136b |
| Sha1 | c6eae2916af4e8603c51e6b27b6e6f8b068284b1 |
| Sha256 | a007111bc2e22b8f34440012d21d7e265d0c349b9e2b2aa2568397238974ec08 |
| Sha384 | 77fa9b548cc4e2c5aaa7e1a974970f0f330a08d4137cd72767b75d24a98b4245969a21619aa94ac79bb0a23ac3aac419 |
| Sha512 | 0e331e925e0747eeb675fa9f9c1c751000543870d1da0b1223ebb20734024e4db35d8386792fbf3e05bc5a6ce7df6479c635d4612d6d4719866359bdd70a442b |
| SSDeep | 393216:d4EIFrol2nfRUTzdKWmLg+iXMCHWUjX4cuI3/PGTAI:dGvfRUTld+iXMb8XNH/O7 |
| TLSH | 88E6335864D413F8EAF3417CAFE18692E558F8B42736C69F179403A17E232E14D3EA27 |
PeID
Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>scr:vbs
Shape
pe:exe>scr:vbs
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_7959ddaf.bin (14037213 bytes) |
| Info | PDB Path: t$mn |