Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 047e26b54da91a6839519d0d49f9a8e2
Sha1 23455d7254b59153d41d0189512477aafb944332
Sha256 e68f2fd161378cad6e3a51312b21a87971851d59a59257be6b4f8a868cc18569
Sha384 298ba33d67d29db5bc41c858dcf4a3027f688efa48a85d71b4046db812a6be1ac69e7d3c2e461cb8d3b3374cd9e3532e
Sha512 cba9acc7321308b036a6a806c2257b0f2845f32ca0b2a406cea1d89d6caf9651ca821aed4f533b67db38cb2a629c857a3e7e06106e4640bfebcabf9f0ca92d7f
SSDeep 48:qgA36+tdATh0F2aA+COk6wmkZXxvckKNZFhQDi+OkRO78WMUW/u:9A3ghgLvwdHOZ8s2O7RMUWW
TLSH 2B5174CB540B8D470AB24A6AD1450D1ECEE4D35F5637C868BD5CE80D5B38268A3A60BE
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
msihuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
msiexehuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
msihuhuhuhu
047e26b54da91a6839519d0d49f9a8e2
Command (COM trace) #2 UNKNWOWNmalicious
msiexehuhuhuhuhuhuhuhuhuhuhu
047e26b54da91a6839519d0d49f9a8e2
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
047e26b54da91a6839519d0d49f9a8e2
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
047e26b54da91a6839519d0d49f9a8e2
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
047e26b54da91a6839519d0d49f9a8e2
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙