Malicious
Malicious

7936699d4629dd47e74d3e6a60476a3b

VBScript
MD5: 7936699d4629dd47e74d3e6a60476a3b
Size: 481.09 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7936699d4629dd47e74d3e6a60476a3b
Sha1 9fe34abdae9bac8711ec2e3793426d1f3f8d600c
Sha256 ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc
Sha384 59ebe0ac61c708397c3f65390d5675b6bbca814382fc20f1503fa8887fd378994e6b0f94cfd7b742913a1ece11f6fdd3
Sha512 bbccf567e17da5c1582188a3117221372772644df224306f915330e3312ce61c54cef5bf7d49c88f402be11a9e8a665f9113379854e31298b46802c64f11e6db
SSDeep 12288:3J9K/CuxnJ3R76vSWgn4iyifij2RI5rCB02:3PKlP7cStXfij2MX2
TLSH 2BA412CE59487A5598D640610F3FBF8803C1DB7BF322A56ECE1D8E9E8B411C64577E22
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
7936699d4629dd47e74d3e6a60476a3b.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat
Shape scr:vbs>scr:bat
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"try{Ahuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
7936699d4629dd47e74d3e6a60476a3b.deobfuscated.vbs
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
"try{Ahuhuhuhuhuhuhuhuhuhuhu
7936699d4629dd47e74d3e6a60476a3b › 7936699d4629dd47e74d3e6a60476a3b.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙