Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 073d4ebf4d71a816477ec1737438a6e0
Sha1 43d2e170757e6a340e5e1682362e76bfd9aa0e52
Sha256 d0987d055e468144f7d34197b7f46830dc765db199f75aa3d75c0cbabb7b487c
Sha384 d1ddb2103c2ca35ddd791e6ffa94fb6ad041e3421963311a7202833e460716b5a12cddc9cd05fbb2b2a6c769fd6388d9
Sha512 e2d929f87ca5ebeedfd204a7802c7be67914bf32448b9df0c16b1d1aba1b5d40e9afac6710e7925686ca529a6695171a037170a225df6b35db413e2ebbe6c3eb
SSDeep 96:eQAKehvm3N8oese5afXoeDTDh3pGddMTiQNm92KC1/XPD:A2So3e5aPnHhPTiB9o/fD
TLSH 8691854AF81AD3B1C2B30EC850B2AC4DF018056855ED4A7EBA1C86FEDE0867F74654BC
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path html~T1027~T1059~T1059.005~T1105>scr:vbs~T1059.005
Shape html>scr:vbs
malicious 2 nodes
Command (COM trace) #1 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Command (COM trace) #1 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
073d4ebf4d71a816477ec1737438a6e0
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙