Malicious
1c23e73a8601a6561a3ff2a092c98abb
VBScript
MD5: 1c23e73a8601a6561a3ff2a092c98abb
Size: 184 B
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 1c23e73a8601a6561a3ff2a092c98abb |
| Sha1 | 4939d1b585d7cdca01eb6ce26f2eeb49d6a20475 |
| Sha256 | 87a9ad0b921959cfb037d784cc37980caac1859ab53cbf3c1fd518c8b40df6b3 |
| Sha384 | f979206509af649e345367633dcf1b9de219fff9fcc284046bd60ba5ac0437052973838d74327ac5f60e7fffbea24e63 |
| Sha512 | 2eba9afb6037135d909be00b319280c128284443536fcd8520fa511497d563c510ccc44c343e3a6c35bbc9ae42ab0715f99b73a1746dab8c245295ab0fdfb467 |
| SSDeep | 3:jblYFFEm8nhQBgSSJJFIGF7dNA0MKBX/EdlcQBoRBjjRwPRjv7upaKnJvXpv:ju3NqhMs8GFlMw8l/BMBjWPhzu0G |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
1c23e73a8601a6561a3ff2a092c98abb
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
1c23e73a8601a6561a3ff2a092c98abb
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
1c23e73a8601a6561a3ff2a092c98abb › 1c23e73a8601a6561a3ff2a092c98abb.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.