Malicious
f41aabf94dcb07e75b0aca59fdf28d05
VBScript
MD5: f41aabf94dcb07e75b0aca59fdf28d05
Size: 3.78 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | f41aabf94dcb07e75b0aca59fdf28d05 |
| Sha1 | ea96eb51a912ff78aea80fe6ea7525343628d968 |
| Sha256 | e66e30257bffaa087c73b91566c75f5333db8b8d787c205028b845e8f9864ca2 |
| Sha384 | d65751c784daf1313944ea437e0843e6888f9bf26f84e73db19e44920bb77565bb77ca2ba15afa3120de88a1c6fceccf |
| Sha512 | 4334ba9a2e9d83c0b6ea226c62f9b82c60c4abeefe5f01815279cdb428e0a85513d2eaf64cba116947423ef348cdb69024122dd087c79b97b171cdf03e5494f5 |
| SSDeep | 98304:QY/gp3v7VyDYLPH6OxAfzcpqLNAZAoquPd:syIaOOzH+ |
| TLSH | 1A06CF1177D7C13AC97E45712AB9EB2E107E7FA51F7444EB27E44AAB0AB14C20271F22 |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 10
STICH kept: 4secondary ignored: 6
bin
5img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
ole:doc>scr:ps1~T1027~T1059.001~T1105
Shape
ole:doc>scr:ps1
malicious
2 nodes
Path
ole:doc>pe:dll~T1059.007>pe:rsrc>bin
Shape
ole:doc>pe:dll>pe:rsrc>bin
technique4 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
f41aabf94dcb07e75b0aca59fdf28d05 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.