Malicious
Malicious

403703d0c7857a87c6b3dc7021c03494

Share on LinkedIn
Print
VBScript
MD5: 403703d0c7857a87c6b3dc7021c03494
Size: 5.5 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 403703d0c7857a87c6b3dc7021c03494
Sha1 090f00a61ea249d80e052813ab9a945eae2683d4
Sha256 96b747a94a2007c42913189440a8a3014f574d134148017cb2cebef4c66520ca
Sha384 404e46051e0d78f2d20f9a4710fbd75414dfcd8355052b5b06b8c83fd3e74fb2938072bfeb14cba3617420e82bf47ee0
Sha512 4c01e2a207b0d39df925f377ac75cff491ecb02d6fca54fc17e1c747916d6760b8026d054507aa6716c57149cc71477acf48c6f9e7202eeb4a61e92c563f1445
SSDeep 24576:8JWJZFOgt5F22LKV/5GyXh5JI7MOK0XiENyHeX4kqN09u2TXzVpeO9765ZaL47HI:CzH+D931
TLSH 31469F606E5859F5EF8C290E90AE6F1D87F082176A33706BFB41DF05BDDA241864B21F
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Base64-Block]
403703d0c7857a87c6b3dc7021c03494.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙