Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2722e8b51ad074ed3b08827981d90021
Sha1 0b90660dc187b7d26c7b6f7a27ee6a2ff9185a76
Sha256 b35d471656ae64cb7dfa2d5b5e879000b2528e81d71314869d47ebdd88e32e49
Sha384 a12fc47568f0e865853177f7126450105fb8e9027ad5b8368849caa5ecfc62693c1788160321b7900d03b57c6bfaf12b
Sha512 0a3ad937e73551ce91793c882546a053f6734a4c2e76b03ddf5ecb00f9605a1d13c871dca922591803af1e112ed4b100378991a5b68a38f1e0d4105bd6d3b3d3
SSDeep 24:57nWMg06sUvWxdJJX/OliCEkRHLE/GHwr9qdd+Bd:5yMTUv4T2NOGHwrYd
TLSH 8533D0002FE51924F3B0553449B5F3F26679FA4A6BE5060F314E16480FA35249EB3F5A
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path img:disk>lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape img:disk>lnk>lnk:cmd>scr:ps1
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
ISO
DiskImage extraction mode: DiscUtils (ISO)
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
2722e8b51ad074ed3b08827981d90021 › ARIB_UPD.LNK
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
2722e8b51ad074ed3b08827981d90021 › ARIB_UPD.LNK › LNK CommandLine › [PowerShell Command]
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
2722e8b51ad074ed3b08827981d90021 › ARIB_UPD.LNK › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙