Malicious
VBScript
MD5: 457fa51ecde2ab20a050758cd482841f
Size: 98.41 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 457fa51ecde2ab20a050758cd482841f |
| Sha1 | 0f72fe8398f5c0eaa994af7769aedb2939c2dad5 |
| Sha256 | 2ca24f488a10fff34fbfcf2d52543872c644690e9a21dfd62583f9c2149e9878 |
| Sha384 | 0aca54638ae2619b1d91f20f93ebf62995dd974487d7dc7280ffd5a477d787b5c0089a2f3eb9a5552022eedbe9c78beb |
| Sha512 | 974f9dfb484d7554398596ad73fe6e72736b0ef68eff7d6a712f5c2b664b7f90fee281a31a903f6ea7c24fd6637c2fd9b1d90eba670cf813325382be320b6ba2 |
| SSDeep | 1536:Y40oQ9dKwOSqANmtK5NXUaRuXWgj0Rms3zR9XGSlkKzNIxGqcVK9Knm03wKEW1QD:tmo |
| TLSH | 5DA38A682644C083ABC63710F8EBBFD4A1647AE6FDDC4B8050244A51D79EEE75C90B9F |
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape
scr:vbs>scr:ps1
malicious
2 nodes
Path
scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape
scr:vbs>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential