Malicious
Malicious

560bf95fc5a4b95beb699c104ccdfbb4

VBScript
MD5: 560bf95fc5a4b95beb699c104ccdfbb4
Size: 278.47 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 560bf95fc5a4b95beb699c104ccdfbb4
Sha1 0411a632bb1b288b4498664468325da85d6cf9c0
Sha256 fa4c85398b343abb47d85ac173762974125bf375059ffa58d5cbc982059aa626
Sha384 7b69c808e0a97fb2f0c002bcbf0b4fffe722172b9f25bcdaae137659573bf1a124baea1fa357c6d056f0ffab41c016a7
Sha512 30b4d37a48d4b14d7b0c124ad575d347ad3204f0dddeff20f4a1f97cb14fd38c965ca716c4052df2046de0f87ef712dd1ba922cd574b73768d606a684771f7d4
SSDeep 384:bRtodBNketbpWExCpIiExeOXvm5uOkVStmy5mWONwuXWOBObrWOBO6CwyPpavIRG:iI
TLSH 474455BE30AD41E4F97CB859F702D654061CE923C51DEAD6A142FB64893D2AC231B1FB
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
560bf95fc5a4b95beb699c104ccdfbb4
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
560bf95fc5a4b95beb699c104ccdfbb4
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙