Malicious
Malicious

871d6eab90f50428b74f6e289dfb4925

VBScript
MD5: 871d6eab90f50428b74f6e289dfb4925
Size: 2.46 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 871d6eab90f50428b74f6e289dfb4925
Sha1 45aa8126df76b5f5c403d37c4352503aec4aa558
Sha256 d3d877e529792a6e07756c840fd62598599f096ae7d4c296f5f5025b4501050d
Sha384 1fdf0f1258326cf7ecffe23082677f07fdfe640efc947d6ccf355d70508e8f58e97d3e85867aafbb208f44f7a96c9611
Sha512 3a28264179d18c1b11abc892e51e837509c65f3bcf025b97df07de3fe89e2f1a714eb7f9520b6edacb5edc1756276de82089c9da17815019676e101559f0c705
SSDeep 48:MLKFRO35t2pUgU3bLhwObos675dk3fRaJC5nX:McR25t9xFwHLNdysJC5X
TLSH E2513256BB0D5362479253E9D80C51F09EA5A81B371B20CB301EC53D0A75068BFB71E6
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
871d6eab90f50428b74f6e289dfb4925
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
871d6eab90f50428b74f6e289dfb4925
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
871d6eab90f50428b74f6e289dfb4925
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
871d6eab90f50428b74f6e289dfb4925
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙