Malicious
9e6a6f934a62e241c8aaa653234979c1
VBScript
MD5: 9e6a6f934a62e241c8aaa653234979c1
Size: 91.46 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 9e6a6f934a62e241c8aaa653234979c1 |
| Sha1 | 343ddec2c0d91c21a1e90f6f3a04b6ed7d654853 |
| Sha256 | e76d28e648a606ad7e0427b533845a49cf240f44c1ad03ed5ead35cff33d6537 |
| Sha384 | c1732279a6ee1e1907f6a166f30adacec9ce2f8f5daaca170a14c06a3091d0fd72524b635f82a84dcd350198bbeb3768 |
| Sha512 | 70b313ab7fada30ea0bda9f3287467f70df38528e01fd2b22b6150adcec3f38b24335a5d09a7ea5d49cadaf17d6735ed59705e4d4914ff9e160c779c24fb9bdf |
| SSDeep | 1536:onuAR1hNDcWoABjpuBI2q7yaKHBCIHYBUBTB8BhlC:onuAR1hNDcWoABjpuBI2q7yaKHBCIHYe |
| TLSH | B193B050673E2C7BDB65CE114F8B2F389B59738E126F48A644CFEB8D5948C812752CAC |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:bat~T1027~T1059.001~T1105>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
Path
scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape
scr:vbs>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
9e6a6f934a62e241c8aaa653234979c1
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
9e6a6f934a62e241c8aaa653234979c1 › 9e6a6f934a62e241c8aaa653234979c1.deobfuscated.vbs
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.