Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1feea0cd98782c360bccb06de3dba76b
Sha1 43d4c1256cb09868d86a702571d19d09b78c6a87
Sha256 0316a0534beb4e367a15ed8406c1ad712969211d0dc58bffa8cf2948768c888d
Sha384 941f39924e46c67cb6bb21f8996a62908024c469ad5bc0e63dd92505df05c02d36540e8cea1ef38667564eac5f913fcd
Sha512 15f48a648374902afea97db011708d0b781affd264de26655ab002ef682fbef162b3710af33dc4ffcec0a9798c4c7b9efa10934985ab90acd4e0ecb71859d07d
SSDeep 384:CoHx5TZO/Xku/iOk+ykpFejktnAAPkjpFe/kN/O5OIjktyx5TZO/XkJFkc/IOnA+:/B3ruorlpTCo2+e0ma1Jml
TLSH 0945548FA351FB465C9B26831506B4D7285DCC62526B3C4DFE38B9C9F800741E2BEA5B
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
1feea0cd98782c360bccb06de3dba76b › 1feea0cd98782c360bccb06de3dba76b.deobfuscated.vbs › [Command #1]
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
1feea0cd98782c360bccb06de3dba76b › 1feea0cd98782c360bccb06de3dba76b.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
1feea0cd98782c360bccb06de3dba76b › 1feea0cd98782c360bccb06de3dba76b.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙