Malicious
Malicious

ae5ae7829e21ae0e9fbf4b7c62531417

Share on LinkedIn
Print
VBScript
MD5: ae5ae7829e21ae0e9fbf4b7c62531417
Size: 10.44 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ae5ae7829e21ae0e9fbf4b7c62531417
Sha1 970b364f63dfa99692e2a829f732d5159b7ada77
Sha256 d6a5ec91bf15db1764e679ad0c72e83231c4558df1b670435db983c387183cab
Sha384 b4b5e0ce75d885d7a0e3ab938e11ccb3366a05a3bd530f1db2b459b993acb88a782f5213eff23c988dd1c05a5686f01a
Sha512 597140344fa232f7caa55102575c3d0e4914630ecc0c25a5becd2056370e984885c5df070d9fb7ced314f37f3bd20647a2ff32f55c4507fe6fdf703c5021feaf
SSDeep 192:g+Sydu0/9do26pC7cDYF7HL1zU1/qVauF/f/7A/egUwbO4PgQC8:gzydVfo/pC41/SaMJ3wb/17
TLSH 2722B463120BE2F2C0F261072677A50EFA41B57755F2B439BDDC4400DF61B5993DA8DA
ae5ae7829e21ae0e9fbf4b7c62531417.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1047~T1059~T1059.001~T1059.005~T1105>scr:bat~T1059.001~T1105>scr:ps1~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #2 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙