Malicious
11cff388397106958dd2a016eefc19cd
VBScript
MD5: 11cff388397106958dd2a016eefc19cd
Size: 88.95 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 11cff388397106958dd2a016eefc19cd |
| Sha1 | eaa12fec5372d00f78d0a2481f5d2f89fb857626 |
| Sha256 | b783a981a31c5c85a77ccf4b572c0cbad8d66237204164a4720663445dbdfb1d |
| Sha384 | 316e89a45450aa6e4a70bd8f91bf6b8d15c42416606ed5c9a838891ba5bd9c59fafbbe151cedd44dabe5510eec549668 |
| Sha512 | 1a8b6961c2844d8c0d414278966bb2a482a40238bda0f9086601831cbdc801566f18b9a04d11afcda6f81926cb40168c47d6b7338fa45b83509dfe8e46fea4b3 |
| SSDeep | 1536:3Z2uxLUqdu/TbhMeFoS2dI/WutKiQ1RFLQRp+WeIjXkDH/b+475XpVbW0ofiuRUw:5Ri |
| TLSH | 5693CB682640C483ABC66710F8E7BED4E1647AE6FDDC4F8050244A51C6DEEE79C90B9F |
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape
scr:vbs>scr:ps1
malicious
2 nodes
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape
scr:vbs>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
11cff388397106958dd2a016eefc19cd
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
11cff388397106958dd2a016eefc19cd › 11cff388397106958dd2a016eefc19cd › .executed › .subscript.vbs
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
11cff388397106958dd2a016eefc19cd › 11cff388397106958dd2a016eefc19cd › .executed › .subscript.vbs › .subscript.vbs.deobfuscated.vbs › [PowerShell Command]
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
11cff388397106958dd2a016eefc19cd › 11cff388397106958dd2a016eefc19cd › .executed › .subscript.vbs › [PowerShell Command]
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
11cff388397106958dd2a016eefc19cd › 11cff388397106958dd2a016eefc19cd › .executed › .subscript.vbs › [PowerShell Command] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.