Malicious
ae5ae7829e21ae0e9fbf4b7c62531417
VBScript
MD5: ae5ae7829e21ae0e9fbf4b7c62531417
Size: 10.44 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | ae5ae7829e21ae0e9fbf4b7c62531417 |
| Sha1 | 970b364f63dfa99692e2a829f732d5159b7ada77 |
| Sha256 | d6a5ec91bf15db1764e679ad0c72e83231c4558df1b670435db983c387183cab |
| Sha384 | b4b5e0ce75d885d7a0e3ab938e11ccb3366a05a3bd530f1db2b459b993acb88a782f5213eff23c988dd1c05a5686f01a |
| Sha512 | 597140344fa232f7caa55102575c3d0e4914630ecc0c25a5becd2056370e984885c5df070d9fb7ced314f37f3bd20647a2ff32f55c4507fe6fdf703c5021feaf |
| SSDeep | 192:g+Sydu0/9do26pC7cDYF7HL1zU1/qVauF/f/7A/egUwbO4PgQC8:gzydVfo/pC41/SaMJ3wb/17 |
| TLSH | 2722B463120BE2F2C0F261072677A50EFA41B57755F2B439BDDC4400DF61B5993DA8DA |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1047~T1059~T1059.001~T1059.005~T1105>scr:bat~T1059.001~T1105>scr:ps1~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | & huhuhuhu |
| Payload Destination | & huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #2
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | & huhuhuhu |
| Payload Destination | & huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Dropped path (COM trace) #2
PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.