Malicious
57b7e50ba69937dcf02a636960f3794b
VBScript
MD5: 57b7e50ba69937dcf02a636960f3794b
Size: 2.18 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 57b7e50ba69937dcf02a636960f3794b |
| Sha1 | ac7c01d513d2eccf84c1fa03dce9e736e0a961af |
| Sha256 | 02b3058057d9bd512199f9a350f02952bb5104950f3c5eb72d4c439fc6403665 |
| Sha384 | 52c6e5daae2d26cdf2996c2dba545f4f71bb530ce22be295aa7401022a14bb3e850377e46c44be39df276f9c0e859cd4 |
| Sha512 | b92c9da9d3af7e8fd558e95ce9222aa78de65682909c51c8263810fb781f98754ea0d5dd7548487a737f4035438d0a4816701737e195a6bdc6e2e9f8f8e978d6 |
| SSDeep | 24:ixip3Mb/AG0bjKvOg5ZYM+BXcpNTETDDPz4vzUZuLIJUXNULWMCawYHVdR3HMGlq:iHYGL+Xc0fDLK59Ri/wZAc |
| TLSH | 8E41C04FE20CDBD28CB23AE5D9C1C42AF9E13A2315451B54B52EA09CCFB7AC5D98D0D9 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
Deobfuscated PowerShell
UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b › 57b7e50ba69937dcf02a636960f3794b.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.