Malicious
Malicious

53b99807c92c8f835297907accdd7d62

VBScript
MD5: 53b99807c92c8f835297907accdd7d62
Size: 247.89 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 53b99807c92c8f835297907accdd7d62
Sha1 1cf63319109f708ca6d8cfa16ef9e11deb9d0848
Sha256 e174a7fd7d054ab5962f7b2a40965ba45125fa6b44b4962e932b09e80a3c7e57
Sha384 f879505d464f381e3ed36c66775a45ca34a192940aa4761134ec440f25d5c76929c8ca6549f1f443a59a96aee8ec6232
Sha512 b666ed79212baf01e6c28406088e23aaf493fa8388671197518c8ec9eb3fbdb83f4d55d1e16dc9ec7d9499b9a999c4236656a6892419ed2a12e72796e891c53b
SSDeep 192:bclgYBblPYBSMH7wYBDzH74gYQsjojigJIxCGSsjo7igJpj2tigJlm0pTxQpTfn3:bwmMGJ
TLSH D4346580B86E98A486770BE1D2C95FC8FD484BFE96DB5951B222C2752778F340C349ED
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
53b99807c92c8f835297907accdd7d62
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
53b99807c92c8f835297907accdd7d62
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙