Malicious
Malicious

9e6a6f934a62e241c8aaa653234979c1

VBScript
MD5: 9e6a6f934a62e241c8aaa653234979c1
Size: 91.46 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 9e6a6f934a62e241c8aaa653234979c1
Sha1 343ddec2c0d91c21a1e90f6f3a04b6ed7d654853
Sha256 e76d28e648a606ad7e0427b533845a49cf240f44c1ad03ed5ead35cff33d6537
Sha384 c1732279a6ee1e1907f6a166f30adacec9ce2f8f5daaca170a14c06a3091d0fd72524b635f82a84dcd350198bbeb3768
Sha512 70b313ab7fada30ea0bda9f3287467f70df38528e01fd2b22b6150adcec3f38b24335a5d09a7ea5d49cadaf17d6735ed59705e4d4914ff9e160c779c24fb9bdf
SSDeep 1536:onuAR1hNDcWoABjpuBI2q7yaKHBCIHYBUBTB8BhlC:onuAR1hNDcWoABjpuBI2q7yaKHBCIHYe
TLSH B193B050673E2C7BDB65CE114F8B2F389B59738E126F48A644CFEB8D5948C812752CAC
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:bat~T1027~T1059.001~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1047~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005~T1105
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
9e6a6f934a62e241c8aaa653234979c1
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
9e6a6f934a62e241c8aaa653234979c1 › 9e6a6f934a62e241c8aaa653234979c1.deobfuscated.vbs
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙