Malicious
Malicious

9f248a15d76f3e3a55dd407cd7c0dd0c

Share on LinkedIn
Print
VBScript
MD5: 9f248a15d76f3e3a55dd407cd7c0dd0c
Size: 98.29 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9f248a15d76f3e3a55dd407cd7c0dd0c
Sha1 32a2d878a61cb3e4832f30e9b483f84942cb78a3
Sha256 875c512c3ed83c4718213d8c7cc31f076a1f5d9fe1157eb26dd8d7917d8cc27a
Sha384 93329782ce69f5427e2141738b46d1488774910d11fdcbe4c9cfaade6bf103c495adfd39d581fc780a782b04104728d9
Sha512 a177a8c8432181458ac7d2c2fca899ca227e435d953e0c03b7b4d335c53592c815fc0afa1b6bc990204bc5801b22cc573eb7a8401b78ea8fead144d7bb0eda02
SSDeep 1536:DrG55QIBwAHfrqXFBIVJN6c5Vy4tfCkLP9dnXjPfr7THGjOvkscmMW45SFMQdZBq:dw4
TLSH 80A3A9682640C483ABC62710F8EBBED4E1647AD6FDDC4F8050244A51D6AEEF79C50B9F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005>scr:vbs~T1059.005
Shape scr:vbs>scr:ps1>scr:vbs
malicious 3 nodes
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1059.005
Shape scr:vbs>scr:ps1
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙