Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3a5962d2b34b441bbd191936a0c0bec0
Sha1 41bd30de96b38ab31adf51891558c7c69c7d07b2
Sha256 ef05d8c68e1e2b9ea7cfbad9bce3acfbd8b2367a28297d2e4c23d9d9340feca2
Sha384 8cb973783a2a583841c2f84024808754bf3a01b268e1703b79c5c7ff3cc3ad73385f7a6c23b77a9465c02ec6bd7e4c91
Sha512 3905a8258f61bc6afc68dd7eeaffc958641c9c073cd9607c3da00a2080b99d226a357bb1a4e1fdc2bdee52398013ea711e25cd1dc96f05799d05be36735ecb77
SSDeep 48:8XCPNKd1pdAKReMWx1/KRbyDJcd1CkXv3y81bYk:8ONYsM+DmvLbY
TLSH F451C21937F90335E3BB853798B2E6414A36BC12EC568BAE5094978C2CB32159825B7F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape lnk>lnk:cmd>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
wget huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
3a5962d2b34b441bbd191936a0c0bec0
Deobfuscated PowerShell UNKNWOWNmalicious
wget huhuhuhuhuhuhuhuhuhuhu
3a5962d2b34b441bbd191936a0c0bec0 › LNK CommandLine › [PowerShell Command]
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
3a5962d2b34b441bbd191936a0c0bec0 › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙