Malicious
Malicious

2ec5a4d805472352a10492d311a80fa7

Share on LinkedIn
Print
VBScript
MD5: 2ec5a4d805472352a10492d311a80fa7
Size: 5.51 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2ec5a4d805472352a10492d311a80fa7
Sha1 da190ccb0e6cdb6b55f40532a0ee7064d31ba760
Sha256 f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f
Sha384 db0c9fff0292d35eeb21e1660b40d93272a46cf49725b4c6b675dd2597173eeefb2b84ae6a31da4cb5b79baeb373b9ce
Sha512 4d6c96d139a880020d7afafdf4d6cd2a989bc384d1fdbcf1014b2ea7f349a138edaa86a26c3544ffdbb5e77299e9d06117821a066a0446b05c919ab6b7864d79
SSDeep 24576:QYuC2NrO/LXTGqatNo3sk/mUjIo/f8YpQneRZQ5msYFFXNBYWuXT1I365ZaL47Hn:75J0r+D93O
TLSH 71469F606E5859F5EF8C690E90AEAF1D83F042176A33706BFB41DF05BDDA241864B21F
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
2ec5a4d805472352a10492d311a80fa7.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙