Malicious
Malicious

1733c79bc9d392d200ae90726154d54f

VBScript
MD5: 1733c79bc9d392d200ae90726154d54f
Size: 8.3 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1733c79bc9d392d200ae90726154d54f
Sha1 07da26b2f7fc6bf0a1f14b9c31c125259c8324e7
Sha256 db9e55535159db148bef69090be530fd01408c303b67f0f16f658d01c7c5ee6d
Sha384 243011964969163bc7f2d361a90bc95d6ee16fb8dc425d5252fe3ad476bf51a1803a56778a98275cefc08e455e19f8ec
Sha512 0b985e44db5c78b2122a33ef83ffc8935f7aa8c1a47dc98d34e3ba399b37a7cf77cffb579677286bcc846d3d8c917fead61ad14e932869ec60cf91e719f9d839
SSDeep 96:vDn/TpzBoLpNnHRPOtYyL9A7elvD0MEwULVh9Z0Grh0DLcy0jhAuD/Elif/4/qd:7LpzUNn1O3L32MT6cchDD/zf/4/+
TLSH 4402F943BA484A86D5BAC8F408576E17F991713341E59E79FA8CC4900F3932AB3BC16E
Overlay_ba6a1f85.bin
Malicious
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.pdata
.idata
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs~T1059.005
Shape pe:exe>scr:vbs
technique2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_ba6a1f85.bin (4199 bytes)
Info
PDB Path: ta
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Overlay_ba6a1f85.bin
Malicious
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.pdata
.idata
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
1733c79bc9d392d200ae90726154d54f › Overlay_ba6a1f85.bin
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
1733c79bc9d392d200ae90726154d54f › Overlay_ba6a1f85.bin
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙