Malicious
VBScript
MD5: a799cd3a7aafb7d003ea9511db0a3cf6
Size: 4.48 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | a799cd3a7aafb7d003ea9511db0a3cf6 |
| Sha1 | c6d668aaade06d1b9804fee55b8b7098387f2acd |
| Sha256 | fee6353b6b1d8a6efa09b78cc6a32a2cd65e6a90c171e406a162af3c09c5366f |
| Sha384 | 29f02d6d45d71c78b7a94917946c485f1ee10ca85ede193cfd7a7aadc89c2976a52633fa4307ac5a9fd2069425baafad |
| Sha512 | 878e114dbbc7a1b1e11b07c88e61004e099f97d51608f03dcb8f573d0d5d18da6c4152850925a10a726d92f49cf270620f6d0350d5d7d234f42d1ff0022a1805 |
| SSDeep | 24576:Jeh3ASXpPct+tN81SRZbxY9xtedeF5secK9ElPWWRSPy+zxLznelG+dMHYvRXO3B:xx |
| TLSH | 0B269F616E5459F5EF8C6A0E90AE6F1D83F042176A33706BFB41DF04BE9A341864B21F |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
Path
scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:vbs>scr:ps1
malicious
2 nodes
Deobfuscated PowerShell
UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
_
""
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
_
""
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential