Malicious
Malicious

defd2f39ffe525e98a82a0e2258b9942

Share on LinkedIn
Print
VBScript
MD5: defd2f39ffe525e98a82a0e2258b9942
Size: 16.17 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 defd2f39ffe525e98a82a0e2258b9942
Sha1 dfeb76e8cf8c83f8d0545a0b823f9f6670fb9024
Sha256 2b9434c7259c147977de103258084b375cbd8e13e02d0f25dd5876e1cc840a0a
Sha384 3e7869091da21e796170b255015d246015e793ab5b393fb0374303b224aeb3064f1a855b8b75ea63751e1a8c9d5ce5e6
Sha512 62afadcf7b2f85862ab92f03b4a17e3b0e4a2c88911afddc2d63b40fd319296a74a59f154f030fff31983371a00991814ca447a89dfbfd6fb6247f7c81ff8e94
SSDeep 192:7Iw6G9ubZ0etDulAfWd4W/XsSyyU2dZy86L05vbtk1zz6AL5j3f:7IXG9SbO6WiWoyU4Zt6L05q1zz6E9
TLSH 1572C22531047EDE387920BB0CEC5860F3B967309A90DCF67EDB84199B2ADDA9390F45
[Base64-Block@0x00000292]
[Base64-Block-Decoded]
[Base64-Block@0x000005D5]
[Base64-Block-Decoded]
[Base64-Block@0x0000091A]
[Base64-Block-Decoded]
[Base64-Block@0x0000031E]
[Base64-Block-Decoded]
[Base64-Block@0x00000662]
[Base64-Block-Decoded]
[Base64-Block@0x000009A8]
[Base64-Block-Decoded]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path scr:vbs~T1027~T1059~T1059.001~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059~T1059.001~T1059.005>scr:ps1~T1027~T1059.001>enc:b64
Shape scr:vbs>scr:ps1>enc:b64
malicious 3 nodes
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙