Malicious
5dd6d5c2a5f03fa2f5688f3d6114ec73
VBScript
MD5: 5dd6d5c2a5f03fa2f5688f3d6114ec73
Size: 124.53 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 5dd6d5c2a5f03fa2f5688f3d6114ec73 |
| Sha1 | 31096a70fe860ee1a60b3a2b0aa6cfb9651e2c58 |
| Sha256 | 4291caf2406a2efbf1fab6d62d3491eacf05e8399dff5e52e82e1a31a1208574 |
| Sha384 | 11806a8c8b7007e190b80cb8bfbbc7ce8409f99ad8e41c36498fa74a715a7acf1bd6abdc33b8b40990d76c592a9fa5c6 |
| Sha512 | 3ecedb75b42cfd43a9d850f2d4b804ec3e583f7cee3032ca27afabbc08d9dafb933590cff4e650a8233f5ef17ceb20d4794ea9785ab1e8324fc75a2bf1b75ab3 |
| SSDeep | 768:8OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOwwwwwwwwwwwwwwwwwwwwwwwwwwwwR:i |
| TLSH | 52C339A0ED942A13FF860CFEF958BDCC7F57004D051A6096AB20EF52BAF10D1762BA55 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059~T1059.005~T1105
Shape
scr:vbs
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL (COM trace) #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL (COM trace) #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Command (COM trace) #2
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Trace COM ordonnée
UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.