Malicious
Malicious

11cff388397106958dd2a016eefc19cd

Share on LinkedIn
Print
VBScript
MD5: 11cff388397106958dd2a016eefc19cd
Size: 88.95 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 11cff388397106958dd2a016eefc19cd
Sha1 eaa12fec5372d00f78d0a2481f5d2f89fb857626
Sha256 b783a981a31c5c85a77ccf4b572c0cbad8d66237204164a4720663445dbdfb1d
Sha384 316e89a45450aa6e4a70bd8f91bf6b8d15c42416606ed5c9a838891ba5bd9c59fafbbe151cedd44dabe5510eec549668
Sha512 1a8b6961c2844d8c0d414278966bb2a482a40238bda0f9086601831cbdc801566f18b9a04d11afcda6f81926cb40168c47d6b7338fa45b83509dfe8e46fea4b3
SSDeep 1536:3Z2uxLUqdu/TbhMeFoS2dI/WutKiQ1RFLQRp+WeIjXkDH/b+475XpVbW0ofiuRUw:5Ri
TLSH 5693CB682640C483ABC66710F8E7BED4E1647AE6FDDC4F8050244A51C6DEEE79C90B9F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙