Malicious
Malicious

f291c9311c17d8da82db7d3de027218c

VBScript
MD5: f291c9311c17d8da82db7d3de027218c
Size: 5.63 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f291c9311c17d8da82db7d3de027218c
Sha1 0931356d46971b3d0982a40d3c862ba6bee95f56
Sha256 fffa5be744fc2315cdec4636a6c098c31ca40794a902883362badf0ac3f0c5bd
Sha384 12ad43d3f4ab7ee71105264b94a4d108f5b045fdb5fed73a6c435694d5d522c80d5607de79e9f6367681093ea52ce7fa
Sha512 256ce3af3c91fae8056b9ab4fffc198fa90c689174e0fb914b45377ef4615cb4b680506af660c37dbe2bb9c84ff5c59f1f9bcdd38e15a63607f3f2b23a8d4503
SSDeep 49152:OynvPr137EcEDnXzlfZ4jn6OIB0juKTAnvhSxxrLJc9/pOvCZUQyFdm0jid3Goxx:3
TLSH 4C4623335B89592FCAB07375B01E6D227E6F4603424CF29669DCA07637FBBC5422E894
PDF @0x00506800
_Pedid805120IZ68GG_FESMZZRHXY-Vrfcejyu.vbs
Malicious
_Pedid805120IZ68GG_FESMZZRHXY-Vrfcejyu.vbs.deobfuscated.vbs
~
[Authenticode]_11565f91.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_BITMAP
ID:03E8
ID:1025
RT_DIALOG
ID:07D0
ID:1025
ID:07DE
ID:1025
ID:07E0
ID:1025
RT_STRING
ID:00BC
ID:1025
ID:00BD
ID:1025
ID:00BE
ID:1025
ID:00BF
ID:1025
ID:00C0
ID:1025
ID:00C1
ID:1025
RT_VERSION
ID:0001
ID:1025
[Authenticode]_0a7637a0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
queffq
mcqqm
lcbbt
jhpyp
bhouhv2.pdf
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 8 0-preview.png
#Stream obj 7 0
gssstv1.pdf
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 6 0-preview.png
Structure
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 2secondary ignored: 4
bin 3img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs>scr:vbs~T1027~T1059.005
Shape scr:vbs>scr:vbs
technique2 nodes
Path scr:vbs>pdf
Shape scr:vbs>pdf
2 nodes
Name Value
ISO
DiskImage extraction mode: DiscUtils (ISO)
Version
1.3
Author
Author
CreationDate
D:20240709170114Z
Creator
XSL-FO http://www.w3.org/1999/XSL/Format
Keywords
keyword1, keyword2
Subject
Subject
Title
Title
Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
/Author
Author
/Keywords
keyword1, keyword2
/CreationDate
D:20240709170114Z
/Title
Title
/Creator
XSL-FO http://www.w3.org/1999/XSL/Format
/Subject
Subject
/Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
Version
1.3
Author
Author
CreationDate
D:20240725182452Z
Creator
XSL-FO http://www.w3.org/1999/XSL/Format
Keywords
keyword1, keyword2
Subject
Subject
Title
Title
Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
/Author
Author
/Keywords
keyword1, keyword2
/CreationDate
D:20240725182452Z
/Title
Title
/Creator
XSL-FO http://www.w3.org/1999/XSL/Format
/Subject
Subject
/Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
Version
1.3
Author
Author
CreationDate
D:20240709170114Z
Creator
XSL-FO http://www.w3.org/1999/XSL/Format
Keywords
keyword1, keyword2
Subject
Subject
Title
Title
Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
/Author
Author
/Keywords
keyword1, keyword2
/CreationDate
D:20240709170114Z
/Title
Title
/Creator
XSL-FO http://www.w3.org/1999/XSL/Format
/Subject
Subject
/Producer
Fonet, Version=1.0.0.0, Culture=neutral, PublicKeyToken=52effa152c4a9dc6, 1.0.0.0
PDF @0x00506800
_Pedid805120IZ68GG_FESMZZRHXY-Vrfcejyu.vbs
Malicious
_Pedid805120IZ68GG_FESMZZRHXY-Vrfcejyu.vbs.deobfuscated.vbs
~
[Authenticode]_11565f91.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_BITMAP
ID:03E8
ID:1025
RT_DIALOG
ID:07D0
ID:1025
ID:07DE
ID:1025
ID:07E0
ID:1025
RT_STRING
ID:00BC
ID:1025
ID:00BD
ID:1025
ID:00BE
ID:1025
ID:00BF
ID:1025
ID:00C0
ID:1025
ID:00C1
ID:1025
RT_VERSION
ID:0001
ID:1025
[Authenticode]_0a7637a0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
queffq
mcqqm
lcbbt
jhpyp
bhouhv2.pdf
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 8 0-preview.png
#Stream obj 7 0
gssstv1.pdf
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 6 0-preview.png
Structure
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙