Malicious
Malicious

5aab6a0c4bd641570f9851ad9e3170b6

VBScript
MD5: 5aab6a0c4bd641570f9851ad9e3170b6
Size: 278.47 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 5aab6a0c4bd641570f9851ad9e3170b6
Sha1 95233ee1ca7354f7f5c12cef2874ea6ef4dc775d
Sha256 4aec2da75423bd7457ae135d3118e308339756fa89cffdd0e78fd85be00a97cf
Sha384 fd41d063cde9883f1167fcfa508e1652e1cb1383919f8ca513d90c6e30a021406bd13654be38d0c6b737b2892e8849ac
Sha512 5dc543aa7d3c4507ea2ef4f45a41e7efacd4d7aff1b7de92d4d26fd3e584e3580a395693eab6821ee2ee9d88fcfed48dfcbeda39151f70a8a41ec21978309ad8
SSDeep 3072:yZVmr2P/yb4CISddwwPQxZVmr2P/ybTISddwwP8UbYKd0d1N9DISddwwPGJxv4vL:K
TLSH CD4464C0C6D245CC7320BEEBF2AAF86B3254EE59C1B8523E50D3D664624AFE44CCB559
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
5aab6a0c4bd641570f9851ad9e3170b6
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5aab6a0c4bd641570f9851ad9e3170b6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙