Malicious
Malicious

1c23e73a8601a6561a3ff2a092c98abb

Share on LinkedIn
Print
VBScript
MD5: 1c23e73a8601a6561a3ff2a092c98abb
Size: 184 B
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1c23e73a8601a6561a3ff2a092c98abb
Sha1 4939d1b585d7cdca01eb6ce26f2eeb49d6a20475
Sha256 87a9ad0b921959cfb037d784cc37980caac1859ab53cbf3c1fd518c8b40df6b3
Sha384 f979206509af649e345367633dcf1b9de219fff9fcc284046bd60ba5ac0437052973838d74327ac5f60e7fffbea24e63
Sha512 2eba9afb6037135d909be00b319280c128284443536fcd8520fa511497d563c510ccc44c343e3a6c35bbc9ae42ab0715f99b73a1746dab8c245295ab0fdfb467
SSDeep 3:jblYFFEm8nhQBgSSJJFIGF7dNA0MKBX/EdlcQBoRBjjRwPRjv7upaKnJvXpv:ju3NqhMs8GFlMw8l/BMBjWPhzu0G
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙