Malicious
Malicious

97e8547c52abd5aedcfc106cfa93aec4

Share on LinkedIn
Print
VBScript
MD5: 97e8547c52abd5aedcfc106cfa93aec4
Size: 5.49 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 97e8547c52abd5aedcfc106cfa93aec4
Sha1 60dc099c833b0a359e291c2a4ef102557f88ad6e
Sha256 95821f98505ad6076ee47fb16453283f5191288be89197974f3b50362354a0e4
Sha384 bfada10fbde39c05190a8fdd2935622714fe6f2f15a21139d074ab5929a80ac6bb197096d689db9a910159d300f5174a
Sha512 5ec40e51fca0c91f8bab82cc7f253fe96cdc401b6f62b8c004ed84b1ac438444634bdaa39d569c754cde95dcdb5c34049d44ec98f4d1f1388e65243a26dd25e5
SSDeep 24576:wquWMIFXGGh5r22jm2geg583tt+l0UyksKnx8j1u00sYNDXvRZx2BJ34xAmmsW/F:HKiK+f
TLSH C9468F616E5859F5EF8C290E90AE6F1D87F042176A33706BFB41DF04BEDA241864B21F
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Base64-Block@0x0000028C]
[Base64-Block-Decoded]
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Path scr:vbs~T1027~T1059.001>enc:b64
Shape scr:vbs>enc:b64
technique2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙