Malicious
Malicious

3720d7f15181bfff196de27a81f080d0

VBScript
MD5: 3720d7f15181bfff196de27a81f080d0
Size: 61.44 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3720d7f15181bfff196de27a81f080d0
Sha1 dd402a3ff43f69bddfaaa3bb1fb26cbeb5b0b353
Sha256 1f95f829dcfea47cc5ff79212d2b08254c4acf71ca70263dafdb7a9ab5c01292
Sha384 4b0e1301b416dd95b0fa90c135333421d1d0b52b8bcf97cd5a2f4b792c39e24f1e554269cb022fae4d1b5dc820f78241
Sha512 703b93f24e47e7f454d099a366f30f0a476414b0b804e14cdc64da43cffde49746ffa19e977d6a97025f57d60683f982559752fb5d2f8db3632c2bc4946fd85d
SSDeep 768:8P1hnNGAkeWMDCOGM3jShfS0huDfObgdvXpJtXwGlGbp3Q8W2VWr2hfS0h:2/NGxoDRx3280hubOoXPl8pAb280h
TLSH BC534F3AD630FC91C75D327086661D9A21A86D56D7B30E64DB093DFE3D32780EF26688
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
3720d7f15181bfff196de27a81f080d0.deobfuscated.vbs
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc~T1027~T1059.005>scr:vbs>scr:ps1~T1027~T1059.001
Shape ole:doc>scr:vbs>scr:ps1
malicious 3 nodes
Path ole:doc~T1027~T1059.005>bin
Shape ole:doc>bin
technique2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
-once huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
3720d7f15181bfff196de27a81f080d0.deobfuscated.vbs
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
-once huhuhuhuhuhuhuhuhuhuhu
3720d7f15181bfff196de27a81f080d0 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [Base64-Block] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙