Malicious
457fa51ecde2ab20a050758cd482841f
VBScript
MD5: 457fa51ecde2ab20a050758cd482841f
Size: 98.41 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 457fa51ecde2ab20a050758cd482841f |
| Sha1 | 0f72fe8398f5c0eaa994af7769aedb2939c2dad5 |
| Sha256 | 2ca24f488a10fff34fbfcf2d52543872c644690e9a21dfd62583f9c2149e9878 |
| Sha384 | 0aca54638ae2619b1d91f20f93ebf62995dd974487d7dc7280ffd5a477d787b5c0089a2f3eb9a5552022eedbe9c78beb |
| Sha512 | 974f9dfb484d7554398596ad73fe6e72736b0ef68eff7d6a712f5c2b664b7f90fee281a31a903f6ea7c24fd6637c2fd9b1d90eba670cf813325382be320b6ba2 |
| SSDeep | 1536:Y40oQ9dKwOSqANmtK5NXUaRuXWgj0Rms3zR9XGSlkKzNIxGqcVK9Knm03wKEW1QD:tmo |
| TLSH | 5DA38A682644C083ABC63710F8EBBFD4A1647AE6FDDC4B8050244A51D79EEE75C90B9F |
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape
scr:vbs>scr:ps1
malicious
2 nodes
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape
scr:vbs>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs › .subscript.vbs.deobfuscated.vbs › [PowerShell Command]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs › .subscript.vbs.deobfuscated.vbs › [PowerShell Command]
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs › [PowerShell Command]
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
457fa51ecde2ab20a050758cd482841f › 457fa51ecde2ab20a050758cd482841f › .executed › .subscript.vbs › [PowerShell Command] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.