Malicious
Malicious

1a605e4e8fcbe463fb11f6e8780ee205

VBScript
MD5: 1a605e4e8fcbe463fb11f6e8780ee205
Size: 266.82 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1a605e4e8fcbe463fb11f6e8780ee205
Sha1 ef46348a6f2d3aff66253b87b5e5d9d58ce42aff
Sha256 90a67aeb77ebe18ad710bb70dd2d80e1cff9dc1ac0c93004dd6d9b70b4d49da2
Sha384 2d7ef8d322cbfbe82df16776f409f1ea99fb9fea31bb683bbe28556bd372fc3d6d5f83d5021d15d73dc3d9e59838deba
Sha512 4b55d5c0c181f0123f0d7ea77f8121f50610327fa83cb7b6cefb811eaf6858ae8f73231cbe82abe5d227933bb174d0c77a5dafc90036b85a6ffa849382d0cb2a
SSDeep 96:2A3h1NiM8qj+mvt+Sj+mv6j5BDCj+mvTEESDVZENCsEvIRDgGCr+EvIED0m0gDLw:b5VWE7JVsMOPy7uuSFGJ
TLSH 7D4459E430B6BE1C8CAC3E3B64D552CB75BA23B18C2C34390B5E8645B59739AD16BC17
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
1a605e4e8fcbe463fb11f6e8780ee205
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
1a605e4e8fcbe463fb11f6e8780ee205
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙