Malicious
Malicious

b213dd96c7133c5cc62f1183342d6874

Share on LinkedIn
Print
VBScript
MD5: b213dd96c7133c5cc62f1183342d6874
Size: 5.51 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b213dd96c7133c5cc62f1183342d6874
Sha1 ee24de0f16a82862c97b767e872a407e0f3b2847
Sha256 641e47f36c91a4ce819a2bd2bcd54ab000363a8c1e3f17273f04b58a2c4e5e73
Sha384 ae4242e96d6f1de9f673d9fafc1db3d50aec240e4da8ed36cae2422f26e7433b7edca7c8c33f058086499fd2ab177b72
Sha512 756a9e5dfb48ee2576459d8ee176b3ad7329ca7f249527399b463a7191cbd9520c2c12e2215c8d4d0ff3cca50114160bccb1a317214a8d9b9a3ef9527945724d
SSDeep 24576:u7jFe7R7l8UkJCbONMHeZ+2u3RtM2qaDtIhH9NaZlK+65ZaL47HReAZxVYmk5DKh:vVY+D93O
TLSH 03469F606E5859F5EF8C290E90AEAF1D87F042176A33706BFB41DF05BDDA241864B21F
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Base64-Block]
b213dd96c7133c5cc62f1183342d6874.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙