Malicious
VBScript
MD5: ba2eb1dfd68940f310fda0074114a689
Size: 2.01 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ba2eb1dfd68940f310fda0074114a689 |
| Sha1 | cf16f8c0341d9ae0c4e3741e45893e5221822583 |
| Sha256 | 088cbcec6b80eba99eb691968e0f972935aae301e9cb6d1c6133699530dd5621 |
| Sha384 | 90bec3b860b8cb1150cb110abe9c89b3ab05e36f9082340daa1f0cf28c2324c70aeaad1d35acfd8d2c04829218543f51 |
| Sha512 | 3c6a643865a8c41d3bf9d9a157ff204f59e2d4eac7048933af91e2235f9e563fb28e15cd4d7d036dba0463468340c4d68698ffb0083f3d2ad69ffec5243c7394 |
| SSDeep | 49152:ymY0GiQnNgTFzA6qZs6AC5+rxz37RPQfYe+pAxJAbhcQQc:XYMQ0Avv2LRPQfYeqAxObhd |
| TLSH | A995F10276C28472D4BF1230296BD7504BBFB8700E35C56F63EC5A1E2F72691A725BA7 |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 10
STICH kept: 3secondary ignored: 7
bin
5img
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
ole:doc>scr:ps1~T1027~T1059.001~T1105
Shape
ole:doc>scr:ps1
malicious
2 nodes
Path
ole:doc>pe:dll~T1059.007>pe:rsrc>bin
Shape
ole:doc>pe:dll>pe:rsrc>bin
technique4 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #8 | fihuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #10 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #8 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #9 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #8 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #9 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #8
URImalicious
fihuhuhuhu
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential