Malicious
Malicious

e6cb33b3a050c14d4eda1552a482c362

VBScript
MD5: e6cb33b3a050c14d4eda1552a482c362
Size: 84.58 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e6cb33b3a050c14d4eda1552a482c362
Sha1 f8610a1c26081b549bcceb591fe0d35c5abd6b77
Sha256 37db8df2e4dc4767276ab5a7afc645a21c75d3e1b94d9ef25c69d99eacfe1729
Sha384 49a3cc9bdd278087560bf66ed5e275bd2159b2ead5c2820cf98c64c618e3e1c04fe378a1bfcd283607a0592f9aa6e696
Sha512 0ff8249b578de4154cca128336be1d3426ae96dba6dcd1d65ca4318f904f228088f6de01b0888c23928c0152868d5ac3d6424a9020e521246594848801bad848
SSDeep 384:rEpnYWgtgYEQbWJyJeJ5ixJCJpXIJ4yJeJ4L+J7JaJe2yJIJpJlJEJ4yJvJaJ4yb:rMYf6WivWeT8fM8YLz/EznUMAq
TLSH 1583AC9A4E7EEF8CF691C7BBDF9DBF11B5E11CBA58789058D1AA184C402275C48EBC10
Overlay_970e103a.bin.deobfuscated.vbs
Malicious
[Deobfuscated PS]
Malicious
Overlay_970e103a.bin
Malicious
.executed
Malicious
.subscript.vbs.deobfuscated.vbs
Malicious
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.pdata
.idata
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs~T1027~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape pe:exe>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_970e103a.bin (80484 bytes)
Info
PDB Path: ta
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Overlay_970e103a.bin.deobfuscated.vbs
Malicious
[Deobfuscated PS]
Malicious
Overlay_970e103a.bin
Malicious
.executed
Malicious
.subscript.vbs.deobfuscated.vbs
Malicious
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.pdata
.idata
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
e6cb33b3a050c14d4eda1552a482c362 › Overlay_970e103a.bin
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
e6cb33b3a050c14d4eda1552a482c362 › Overlay_970e103a.bin › Overlay_970e103a.bin › .executed › .subscript.vbs
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙