Malicious
VBScript
MD5: 3f7f7b1a9821e4a9d4a83c5c317c66a7
Size: 184 B
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 3f7f7b1a9821e4a9d4a83c5c317c66a7 |
| Sha1 | 7522817f158cdb427e88e5589a2d5b076acecb5f |
| Sha256 | 7874231ce6c0c4f5873986991b98624de17260679955960cd1e96a29e24be3b2 |
| Sha384 | 843edd10925585514d6e566125bc968546e497d5bad44e942b962f322c21c850f8964bbff04648518330442b75bbd7bb |
| Sha512 | dd537dd827209497083c34f279ca5a575a4e1e0fac812d005b9a58c2f4f3c9f2a75024a7af52f4f31c7f4c003c2beb19cb27975505d4b101bc8a61d6ab2238b7 |
| SSDeep | 3:jblYFFEm8nhQBgSSJJFIGF7dNA0MKBX/EdlDhVUq0eBwMWbLZspaKnJvXpv:ju3NqhMs8GFlMw8lDIHeM+0G |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential