Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2ec5a4d805472352a10492d311a80fa7
Sha1 da190ccb0e6cdb6b55f40532a0ee7064d31ba760
Sha256 f88d9094a90f7000a3fb2cd7c981e03357ce2b39df9de5ee1d0742e619e3860f
Sha384 db0c9fff0292d35eeb21e1660b40d93272a46cf49725b4c6b675dd2597173eeefb2b84ae6a31da4cb5b79baeb373b9ce
Sha512 4d6c96d139a880020d7afafdf4d6cd2a989bc384d1fdbcf1014b2ea7f349a138edaa86a26c3544ffdbb5e77299e9d06117821a066a0446b05c919ab6b7864d79
SSDeep 24576:QYuC2NrO/LXTGqatNo3sk/mUjIo/f8YpQneRZQ5msYFFXNBYWuXT1I365ZaL47Hn:75J0r+D93O
TLSH 71469F606E5859F5EF8C690E90AEAF1D83F042176A33706BFB41DF05BDDA241864B21F
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
2ec5a4d805472352a10492d311a80fa7.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
2ec5a4d805472352a10492d311a80fa7.deobfuscated.vbs
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
"$b64=huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › 2ec5a4d805472352a10492d311a80fa7.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
_ "" huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS]
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" & _huhuhuhuhuhuhuhuhuhuhu
2ec5a4d805472352a10492d311a80fa7 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙