Malicious
Document-52848.pdf [...] .vbs
VBScript
MD5: 54f4c9e754136c302009a54e49c39c96
Size: 2.6 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 54f4c9e754136c302009a54e49c39c96 |
| Sha1 | 9a20b9f04222787abaf95f6131b90ccbc3babd94 |
| Sha256 | 7a7b8eef418a8dee833097b2f077d783cecc51e1dd66778d52c54268d422f7d0 |
| Sha384 | dbcecf6d64a777a6032fdcb8419de059a6d47dada1978795f899ea7637abd64735cdd81cf53f3fd82a9ce3ca13ae124c |
| Sha512 | 441ca91bb70a2e6184cf2934cdfdea8fe163629e0b4c9d5ee8ef1df82f8d2b22225336a2aac9230d886b0701afeed3eefaf3ae2d5800a255f35445f514122d81 |
| SSDeep | 48:AyDXYHsggT7pbvxpEqi3jj8ddALhn27YkLpcdAjchnDFXzWdLBYndAlSA6S:AyDXYDg3NvxppiErv448OSc |
| TLSH | FF519467AE59CD3CF8631A1382BAEC2E7E6C05137C52C4C7E06D864436A877853DA40B |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL (COM trace) #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #3
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #4
UNKNWOWNmalicious
cscriphuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL (COM trace) #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96
Command (COM trace) #2
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96
Command (COM trace) #3
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96
Command (COM trace) #4
UNKNWOWNmalicious
cscriphuhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96 › 54f4c9e754136c302009a54e49c39c96.deobfuscated.vbs › [Command #1] › [PowerShell Command]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96 › 54f4c9e754136c302009a54e49c39c96.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96 › 54f4c9e754136c302009a54e49c39c96.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
54f4c9e754136c302009a54e49c39c96 › 54f4c9e754136c302009a54e49c39c96.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.