Malicious
Malicious

39283bf93490034f46841b309f53a7b6

VBScript
MD5: 39283bf93490034f46841b309f53a7b6
Size: 78.64 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 39283bf93490034f46841b309f53a7b6
Sha1 e865b4ab49c641562de243efe61950cf8a36553b
Sha256 bc2ad7f3e659c85f70b62277ae4eb5f334e4b13540424d2b73ea5ddadc01572f
Sha384 c374008cef9e4f3455273ba26aea1f5ea778be361ef8e59a0f1870a8b831af9a85ca21e509bbcb42a2fc9cec9d6bf992
Sha512 a9f93469cb5a6558162afac35580c652ffca30cf5e3cc9c6cda0542bcb07707c892ecc322a9e1381f4c647913075782ec4fdcd37a2f80fd4e52de9b347a859c7
SSDeep 768:363s3+s47gp5pHp5py4BpcptytIpcpnplyNhP2Opq9sptY9Qolp9JZWJwP6/2wCo:hBRg
TLSH B873BCC6CF262E6D45771EA3A0E0FF8785E4348A7D218B58E464D36BC5CD6BD052E232
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105>scr:vbs~T1027~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1>scr:vbs>scr:ps1
malicious 4 nodes
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105>scr:vbs~T1027~T1059.001~T1059.005~T1105>scr:ps1~T1059.001~T1105
Shape scr:vbs>scr:ps1>scr:vbs>scr:ps1
malicious 4 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0] › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0] › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Command #0] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
39283bf93490034f46841b309f53a7b6 › 39283bf93490034f46841b309f53a7b6.deobfuscated.vbs › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command].deobfuscated.vbs › [Deobfuscated PS] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙