Malicious
VBScript
MD5: b213dd96c7133c5cc62f1183342d6874
Size: 5.51 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b213dd96c7133c5cc62f1183342d6874 |
| Sha1 | ee24de0f16a82862c97b767e872a407e0f3b2847 |
| Sha256 | 641e47f36c91a4ce819a2bd2bcd54ab000363a8c1e3f17273f04b58a2c4e5e73 |
| Sha384 | ae4242e96d6f1de9f673d9fafc1db3d50aec240e4da8ed36cae2422f26e7433b7edca7c8c33f058086499fd2ab177b72 |
| Sha512 | 756a9e5dfb48ee2576459d8ee176b3ad7329ca7f249527399b463a7191cbd9520c2c12e2215c8d4d0ff3cca50114160bccb1a317214a8d9b9a3ef9527945724d |
| SSDeep | 24576:u7jFe7R7l8UkJCbONMHeZ+2u3RtM2qaDtIhH9NaZlK+65ZaL47HReAZxVYmk5DKh:vVY+D93O |
| TLSH | 03469F606E5859F5EF8C290E90AEAF1D87F042176A33706BFB41DF05BDDA241864B21F |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
Path
scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:vbs>scr:ps1
malicious
2 nodes
Deobfuscated PowerShell
UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
_
""
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
_
""
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" &
_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential