Malicious
Malicious

e67cdbcc4b5fe7fa07a3d58141be6d87

Share on LinkedIn
Print
VBScript
MD5: e67cdbcc4b5fe7fa07a3d58141be6d87
Size: 175 B
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e67cdbcc4b5fe7fa07a3d58141be6d87
Sha1 d6119c6947af6c011414af3e3066b217cecddff4
Sha256 f88fa992ec10a58553d3adf2b4c1fcc7c12e7a62af2a4ae9c0768e1fa129e500
Sha384 b8df1c84ef2c30e7b1a7cf6747a46dddd2b306bbc8db9d89aca6ec05d54ec520c89aead7fb7ae6b9e7d26fcbde914221
Sha512 0727325361599781a44e905feb340258ff25117d730c3fd5c53064f229befbf63021c4d5e68afaca827839fe7f81b20adb3e9e3c0f13ff9741a536b5d0ff021d
SSDeep 3:jblYFFEm8nhQBgSSJJFIGF7dN0PbKuDK8ErDUhlKNRc0ZspaKnJvXpv:ju3NqhMs8GFIqLRc0S0G
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙