Suspicious
Suspect

fa8e180882f6a9e1b3f841b6dd3c3aa6

VBScript
MD5: fa8e180882f6a9e1b3f841b6dd3c3aa6
Size: 566.27 KB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fa8e180882f6a9e1b3f841b6dd3c3aa6
Sha1 a0a80fea413c1dfe84d93da44b8b2cbe31f790ee
Sha256 272bc2b6085fb18f7c0ed518ea6612953cd6069079fdda15bd2d99b7e5b53e1f
Sha384 eec61fa4ceb01cd6f68f13e1d52b92fd0715bdeeed7722cd6c220caaa220ead43c6d894d14a54308e48cf6d575d7a03f
Sha512 7d2dd58d5ed5c66323228c21c377eacd5f417a1fb81478959165ee0708b1b0276fca7a2ba2f12ad9ad984a09768b0ae3323725b26e932095c2a97f56f53bbf72
SSDeep 6144:27wijBW/IbMAmU+xqYWFw/2IWLA1q1mhkySWi5BfCCXXZWAfgVCDFN7Ea+ytq:wSAmUSqYWFweTmOySWu1ZrI0FNpq
TLSH 8FC49E18B6A402F9E177C274CE574613F7B278491374A9EB03E099A72F236E09B3E751
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.data2
.pvmut
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:rsrc>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.data2
.pvmut
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙