Malicious
Malicious

d1ac0fe6e5a468339625c6291b61b2ca

VBScript
MD5: d1ac0fe6e5a468339625c6291b61b2ca
Size: 1.99 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d1ac0fe6e5a468339625c6291b61b2ca
Sha1 a64fca22fef49f280b17d61bc84e4f7095546101
Sha256 abc492db031c7a2cbbab178dbfba63eeb0520ad7dc72fd62c2e74c8b6f59f42d
Sha384 5e42d9ed07a5b97dbf21cb9f0cbc10c2151d8d2c05da95479ea85336dc4e15194f9c990de5ae66fc1191a69c1b78a3d4
Sha512 11a303fc52f4c8e21cfa2ffcb1e696d455dd349113e442a1967cb736d0ce5f624dc324b6d7d2a6baa46dba444c91584ef6ef529ab6f7e5c16907c77768dac3b7
SSDeep 48:eR9dZVazRBk5OPYUsnboGiouH8VSpMVlruFk06FVLIbIEjSAH:ezdZAtBAqUYzcCMjuy06F9IbIgSo
TLSH 5241257CB0A57E636AB3E34989E4D25C13D2A4158714818FB4EDC81B7E43211776591D
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
URL (COM trace) #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
URL (COM trace) #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
d1ac0fe6e5a468339625c6291b61b2ca
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
d1ac0fe6e5a468339625c6291b61b2ca
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
d1ac0fe6e5a468339625c6291b61b2ca
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙