Malicious
618c7addafef6ad67a62ba86e01a51a8
VBScript
MD5: 618c7addafef6ad67a62ba86e01a51a8
Size: 1.68 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 618c7addafef6ad67a62ba86e01a51a8 |
| Sha1 | eabf988bfbf8be98d847c86470852680960434c3 |
| Sha256 | 51473dd2b6ac0bfc7beae6bdddfd49a55465cd51b9a62383b2b7dc3867bf5e9b |
| Sha384 | b782bc1f83cf2b3f0983ae6459074abe7effee879a9bb86b7067bfdd5d2b908593dcdaaddba64b7f5c3500dad0a1fa01 |
| Sha512 | 25c914d5f209395226c5307e75c1696a857fd08be384399d3c2cbb6542e6daa4655eacd0386998a7a15f4f55f014e393f23ce87319e3e386b2dca7ba22d739a9 |
| SSDeep | 48:eRnfdL6oDOzJN/rEWWAl7AN06MBj9acLywiLp:ePLtAJO1WciBB5JOV |
| TLSH | D531508EB82D91388D228193F6AAF82CCDE04F6AAE731480B5148506CE489BCE64D14B |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1059~T1059.005~T1105
Shape
scr:vbs
technique1 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1
PATHmalicious
C:\Prohuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1
PATHmalicious
C:\Prohuhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
618c7addafef6ad67a62ba86e01a51a8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.