Malicious
Malicious

e6cb33b3a050c14d4eda1552a482c362

Share on LinkedIn
Print
VBScript
MD5: e6cb33b3a050c14d4eda1552a482c362
Size: 84.58 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e6cb33b3a050c14d4eda1552a482c362
Sha1 f8610a1c26081b549bcceb591fe0d35c5abd6b77
Sha256 37db8df2e4dc4767276ab5a7afc645a21c75d3e1b94d9ef25c69d99eacfe1729
Sha384 49a3cc9bdd278087560bf66ed5e275bd2159b2ead5c2820cf98c64c618e3e1c04fe378a1bfcd283607a0592f9aa6e696
Sha512 0ff8249b578de4154cca128336be1d3426ae96dba6dcd1d65ca4318f904f228088f6de01b0888c23928c0152868d5ac3d6424a9020e521246594848801bad848
SSDeep 384:rEpnYWgtgYEQbWJyJeJ5ixJCJpXIJ4yJeJ4L+J7JaJe2yJIJpJlJEJ4yJvJaJ4yb:rMYf6WivWeT8fM8YLz/EznUMAq
TLSH 1583AC9A4E7EEF8CF691C7BBDF9DBF11B5E11CBA58789058D1AA184C402275C48EBC10
Overlay_970e103a.bin.deobfuscated.vbs
Malicious
[Deobfuscated PS]
Malicious
Overlay_970e103a.bin
Malicious
.executed
Malicious
.subscript.vbs.deobfuscated.vbs
Malicious
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.pdata
.idata
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:vbs~T1027~T1059.001~T1059.005~T1105>scr:ps1~T1027~T1059.001~T1105
Shape pe:exe>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_970e103a.bin (80484 bytes)
Info
PDB Path: ta
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙