Suspicious
Suspect

fa8e180882f6a9e1b3f841b6dd3c3aa6

Share on LinkedIn
Print
VBScript
MD5: fa8e180882f6a9e1b3f841b6dd3c3aa6
Size: 566.27 KB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fa8e180882f6a9e1b3f841b6dd3c3aa6
Sha1 a0a80fea413c1dfe84d93da44b8b2cbe31f790ee
Sha256 272bc2b6085fb18f7c0ed518ea6612953cd6069079fdda15bd2d99b7e5b53e1f
Sha384 eec61fa4ceb01cd6f68f13e1d52b92fd0715bdeeed7722cd6c220caaa220ead43c6d894d14a54308e48cf6d575d7a03f
Sha512 7d2dd58d5ed5c66323228c21c377eacd5f417a1fb81478959165ee0708b1b0276fca7a2ba2f12ad9ad984a09768b0ae3323725b26e932095c2a97f56f53bbf72
SSDeep 6144:27wijBW/IbMAmU+xqYWFw/2IWLA1q1mhkySWi5BfCCXXZWAfgVCDFN7Ea+ytq:wSAmUSqYWFweTmOySWu1ZrI0FNpq
TLSH 8FC49E18B6A402F9E177C274CE574613F7B278491374A9EB03E099A72F236E09B3E751
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.data2
.pvmut
.fptable
.rsrc
.reloc
Resources
RT_RCDATA
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:rsrc>pe:dll
3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙