Malicious
9d745d57df160d8d4e9fca33ea990c7d
VBScript | MD5: 9d745d57df160d8d4e9fca33ea990c7d | Size: 1.19 KB | text/vbscript
VBScript
MD5: 9d745d57df160d8d4e9fca33ea990c7d
Size: 1.19 KB
text/vbscript
Scripting.FileSystemObject
WScript.Shell
MSXML2.XMLHTTP
DeObfuscated
VBScript
T1059.005
Obfuscated
Infection Chain
Summary by MalvaGPT
Characteristics
Hash | Hash Value |
---|---|
MD5 | 9d745d57df160d8d4e9fca33ea990c7d
|
Sha1 | 0cb1e14471444c4d8593d58d54901b71fbaec911
|
Sha256 | 55e19f8fe96ec0d680c2ea46c958f8c6c622bc44b83fcb5182ebeaef167f02fa
|
Sha384 | 769f3d8c58299b4eeafe19f0b3f6c32dd47afbfcc9eba1d3fc9faf2404f28d67d470e08241457a7ae333fdbddda4294e
|
Sha512 | 44c6515f9d56cbcf724638f140a32a60e206e7384aa0262d6e338617fbc561b3d0340c540650bfe6c210099baef0e0d790f6c1a57bcd43d7e0ccda80a79e5b72
|
SSDeep | 24:gzJSjn0lAW31D0CUS3b3koMG65eNr3kJztGMG6JRLRucgp4MnDguTxa++:aLDXd3b3kT+R3kJJl7R5gzDgEi
|
TLSH | D521E118681CCB1E471613D0F2B5681D9F31C19BACA0E22816F0CC4D55E17B637F9657
|
File Structure
9d745d57df160d8d4e9fca33ea990c7d
Scripting.FileSystemObject
WScript.Shell
MSXML2.XMLHTTP
DeObfuscated
VBScript
T1059.005
Obfuscated
Malicious
9d745d57df160d8d4e9fca33ea990c7d.deobfuscated.vbs
DeObfuscated
VBScript
T1059.005
Malicious
Malware Configuration - URLs in VBA/VBS Code
Config. Field0 | Value |
---|---|
URL #1 | https://raw.githubusercontent.com/USATIKTOKER/dash/main/coded.txt |
URL #2 | https://raw.githubusercontent.com/USATIKTOKER/NEWADD/main/main.txt |
9d745d57df160d8d4e9fca33ea990c7d (1.19 KB)
File Structure
9d745d57df160d8d4e9fca33ea990c7d
Scripting.FileSystemObject
WScript.Shell
MSXML2.XMLHTTP
DeObfuscated
VBScript
T1059.005
Obfuscated
Malicious
9d745d57df160d8d4e9fca33ea990c7d.deobfuscated.vbs
DeObfuscated
VBScript
T1059.005
Malicious
Characteristics
Malware Configuration - URLs in VBA/VBS Code
Config. Field0 | Value |
---|---|
URL #1 | https://raw.githubusercontent.com/USATIKTOKER/dash/main/coded.txt |
URL #2 | https://raw.githubusercontent.com/USATIKTOKER/NEWADD/main/main.txt |
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.