Malicious
Malicious

457fa51ecde2ab20a050758cd482841f

Share on LinkedIn
Print
VBScript
MD5: 457fa51ecde2ab20a050758cd482841f
Size: 98.41 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 457fa51ecde2ab20a050758cd482841f
Sha1 0f72fe8398f5c0eaa994af7769aedb2939c2dad5
Sha256 2ca24f488a10fff34fbfcf2d52543872c644690e9a21dfd62583f9c2149e9878
Sha384 0aca54638ae2619b1d91f20f93ebf62995dd974487d7dc7280ffd5a477d787b5c0089a2f3eb9a5552022eedbe9c78beb
Sha512 974f9dfb484d7554398596ad73fe6e72736b0ef68eff7d6a712f5c2b664b7f90fee281a31a903f6ea7c24fd6637c2fd9b1d90eba670cf813325382be320b6ba2
SSDeep 1536:Y40oQ9dKwOSqANmtK5NXUaRuXWgj0Rms3zR9XGSlkKzNIxGqcVK9Knm03wKEW1QD:tmo
TLSH 5DA38A682644C083ABC63710F8EBBFD4A1647AE6FDDC4B8050244A51D79EEE75C90B9F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape scr:vbs>scr:ps1
malicious 2 nodes
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙