Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0ac94c10f89a62b68ffc79bb8f487446
Sha1 7272dc7ba85d30bedaa76996c434134f8f7251c5
Sha256 0ea0784ffc19dc8536eb8f9cc1649e98d6f40cd0c4e89e22aec8b11492146a09
Sha384 e9395cfecd76558e9c9053ef02ab0396e017b54b93a1ca86fa444d501375cf198181108241d164c0bcced9852857a780
Sha512 0a3a6c8144231bf7f151b78b17e16d176b208d4caa64972c503f0a97186d27703f143bd787781c24173e12b96a77da66f33ea5f0c13034cddd5e958c82b241f6
SSDeep 3072:xUeW4gdksdoxmoXqNyI4nkXgWWb6E4+j8hHJapNP2p1pJAXkTACN/uP0z:/vxqN/gWWGEt8INep1piSE2
TLSH 490412116B2A8D6B57F113B090BB1D0966940E0F512EEA7C7FDCD84E5F6CBA0612F92C
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
[Base64-Block]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:bat>scr:ps1
malicious 3 nodes
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"C:\Wihuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
schtashuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
[Base64-Block]
No malware configuration was found at this point.
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446
Deobfuscated PowerShell UNKNWOWNmalicious
"C:\Wihuhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446 › 0ac94c10f89a62b68ffc79bb8f487446.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446 › 0ac94c10f89a62b68ffc79bb8f487446.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446 › 0ac94c10f89a62b68ffc79bb8f487446.deobfuscated.vbs › [Command #2] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
schtashuhuhuhuhuhuhuhuhuhuhu
0ac94c10f89a62b68ffc79bb8f487446 › 0ac94c10f89a62b68ffc79bb8f487446.deobfuscated.vbs › [Command #4] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙