Malicious
Malicious

618c7addafef6ad67a62ba86e01a51a8

VBScript
MD5: 618c7addafef6ad67a62ba86e01a51a8
Size: 1.68 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 618c7addafef6ad67a62ba86e01a51a8
Sha1 eabf988bfbf8be98d847c86470852680960434c3
Sha256 51473dd2b6ac0bfc7beae6bdddfd49a55465cd51b9a62383b2b7dc3867bf5e9b
Sha384 b782bc1f83cf2b3f0983ae6459074abe7effee879a9bb86b7067bfdd5d2b908593dcdaaddba64b7f5c3500dad0a1fa01
Sha512 25c914d5f209395226c5307e75c1696a857fd08be384399d3c2cbb6542e6daa4655eacd0386998a7a15f4f55f014e393f23ce87319e3e386b2dca7ba22d739a9
SSDeep 48:eRnfdL6oDOzJN/rEWWAl7AN06MBj9acLywiLp:ePLtAJO1WciBB5JOV
TLSH D531508EB82D91388D228193F6AAF82CCDE04F6AAE731480B5148506CE489BCE64D14B
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1059~T1059.005~T1105
Shape scr:vbs
technique1 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Prohuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Prohuhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙