Malicious
Malicious

2e41971bf894a0d4b1ab2627d822338a

VBScript
MD5: 2e41971bf894a0d4b1ab2627d822338a
Size: 184 B
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2e41971bf894a0d4b1ab2627d822338a
Sha1 ac4cd6514a7bcb1e9ddd46b123fd2b27c16bb620
Sha256 066570caeed24461a82c5ecd715bfde6d04fa86e8b2db680572217318e54d53f
Sha384 e629c92b21cb98e27a9f60f09b1f72da1acaf4ee27ad9e89758c07fa6fca0f735d868aa9515bfd2d18b9293ae54701b9
Sha512 d3799941f3937f0fff7ec8c4ac2bb6c065c73fc304ab2a0d670f582330b4d17043ab1927dcc0b59a898a83818172a7c40bcbb33be31fbc4ec59f939ca3ecc0fd
SSDeep 3:jblYFFEm8nhQBgSSJJFIGF7dNA0MKBX/EdlxCCRniDjrFD3CpaKnJvXpv:ju3NqhMs8GFlMw8lxCCR4Xs0G
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
2e41971bf894a0d4b1ab2627d822338a
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
2e41971bf894a0d4b1ab2627d822338a
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
2e41971bf894a0d4b1ab2627d822338a › 2e41971bf894a0d4b1ab2627d822338a.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙