Malicious
4396ace58f4094a290e3d3751d99b58d
VBScript
MD5: 4396ace58f4094a290e3d3751d99b58d
Size: 5.49 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 4396ace58f4094a290e3d3751d99b58d |
| Sha1 | e36dc4776b20d0326f53cd9b756643f9ee63d681 |
| Sha256 | 2d9dcf915d0ad99f33c051fa908081a948593bf4763a00a436e740b5ffb13d5d |
| Sha384 | dfd2a866d2bb70102623f9d5434345e76a6e3ba0712615e6fceee68aa58b4a2772729bf5d49ee7beefdd935a9bd5deb7 |
| Sha512 | d4a9b4fe79324d8630a7b8f1646d1b569f30b12d949e1ea7b9503d5556cd632cf3f33627da419a4aa375e9b8cf26662b0e0aeb9ad6e33bdc1d1665a7bf19527a |
| SSDeep | 96:1zA+/CEUxmfg4myTgM889R/nRD/3c/hsO+hs01g2QqUi0:1/P5XTgM883/n5/s/SOMs0ghx |
| TLSH | 61B165569E19D7B0C4B056404A93980DFA804DA3DA60FC6EFD8C80089F39FAF52E54DA |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1047~T1059~T1059.005
Shape
scr:vbs
malicious
1 nodes
Dropped path (COM trace) #1
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #2
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Dropped path (COM trace) #1
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
4396ace58f4094a290e3d3751d99b58d
Dropped path (COM trace) #2
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
4396ace58f4094a290e3d3751d99b58d
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
4396ace58f4094a290e3d3751d99b58d
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4396ace58f4094a290e3d3751d99b58d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.