Malicious
VBScript
MD5: e67cdbcc4b5fe7fa07a3d58141be6d87
Size: 175 B
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | e67cdbcc4b5fe7fa07a3d58141be6d87 |
| Sha1 | d6119c6947af6c011414af3e3066b217cecddff4 |
| Sha256 | f88fa992ec10a58553d3adf2b4c1fcc7c12e7a62af2a4ae9c0768e1fa129e500 |
| Sha384 | b8df1c84ef2c30e7b1a7cf6747a46dddd2b306bbc8db9d89aca6ec05d54ec520c89aead7fb7ae6b9e7d26fcbde914221 |
| Sha512 | 0727325361599781a44e905feb340258ff25117d730c3fd5c53064f229befbf63021c4d5e68afaca827839fe7f81b20adb3e9e3c0f13ff9741a536b5d0ff021d |
| SSDeep | 3:jblYFFEm8nhQBgSSJJFIGF7dN0PbKuDK8ErDUhlKNRc0ZspaKnJvXpv:ju3NqhMs8GFIqLRc0S0G |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential