Malicious
5aab6a0c4bd641570f9851ad9e3170b6
VBScript
MD5: 5aab6a0c4bd641570f9851ad9e3170b6
Size: 278.47 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 5aab6a0c4bd641570f9851ad9e3170b6 |
| Sha1 | 95233ee1ca7354f7f5c12cef2874ea6ef4dc775d |
| Sha256 | 4aec2da75423bd7457ae135d3118e308339756fa89cffdd0e78fd85be00a97cf |
| Sha384 | fd41d063cde9883f1167fcfa508e1652e1cb1383919f8ca513d90c6e30a021406bd13654be38d0c6b737b2892e8849ac |
| Sha512 | 5dc543aa7d3c4507ea2ef4f45a41e7efacd4d7aff1b7de92d4d26fd3e584e3580a395693eab6821ee2ee9d88fcfed48dfcbeda39151f70a8a41ec21978309ad8 |
| SSDeep | 3072:yZVmr2P/yb4CISddwwPQxZVmr2P/ybTISddwwP8UbYKd0d1N9DISddwwPGJxv4vL:K |
| TLSH | CD4464C0C6D245CC7320BEEBF2AAF86B3254EE59C1B8523E50D3D664624AFE44CCB559 |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
5aab6a0c4bd641570f9851ad9e3170b6
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5aab6a0c4bd641570f9851ad9e3170b6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.