Malicious
Malicious

d0cec1850a2d55308369f58291d1f362

VBScript
MD5: d0cec1850a2d55308369f58291d1f362
Size: 61.44 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d0cec1850a2d55308369f58291d1f362
Sha1 7ba2ce48b3f4c2d9745f74e6ac60208d92f0332b
Sha256 b1287ab346d488cf587ff52932119e02113403b9b9a7231e5c95fa0143de1a39
Sha384 f050a646d9520641ddd99c47a39465fb9337469df4c57a53984822862b1590f1f351d5dda315cbeb78c076ce60367b27
Sha512 89d0e82d27552c50730d9a4a3d73f8a850f7b0f158ca3bc36b5875adcba2da10f849af14bc731d182eaf40438c74954945998d7dd23cc7d40a6aad376d9fc540
SSDeep 1536:xHNGxoDRx3280h8ZAOc5ROeqNKHASY80h:pgROdKHAS
TLSH C753313AD630FCD0C75D327086662D9A21986D56C7B34D64DB093DFE3D32B81EB29688
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
d0cec1850a2d55308369f58291d1f362.deobfuscated.vbs
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc~T1027~T1059.005>scr:vbs>scr:ps1~T1027~T1059.001
Shape ole:doc>scr:vbs>scr:ps1
malicious 3 nodes
Path ole:doc~T1027~T1059.005>bin
Shape ole:doc>bin
technique2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
-once huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
d0cec1850a2d55308369f58291d1f362.deobfuscated.vbs
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
-once huhuhuhuhuhuhuhuhuhuhu
d0cec1850a2d55308369f58291d1f362 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [Base64-Block] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙