Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41778c82d112b01f2ced7bd96b19da63
Sha1 51cf0b1a687279eb9dc7a79b0f75d27daf464aab
Sha256 d68a9b3dcbe30b391315c02a65821c185280e00892d7e826ef12ffacafb2ee0c
Sha384 b4c7405ec308e5bec6c11542b19eb52043ae057a8f010ea61462b31430fb6cb326e5ef31ff5844a5c9cdd6e49fd18a23
Sha512 1accd58c2d4f891e4c600267ed0f5ec13ee5dedf5469b45a918ecbb9ed2c5f25ca1a271578ff573738d97e899dfcaa46a7484df3263d48747d53a7050457b0c5
SSDeep 196608:BU3E4CyK2gfv9lSqkeyUIBhaWSS+1Mm+SS3RdnrMqnaRL1etH:Sf4gbCS+1Mm+SmRlQqnEeJ
TLSH CE076D83E85192ECCADDC130C56986A17B303C499B3067D72B21FAB92677BD05B7E394
PeID
Borland Delphi 7 - Nstd EP - ASL sign HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
Malicious
RT_RCDATA
Malicious
ID:0000
Malicious
ID:0
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.rdata
.data
.idata
.symtab
Optional Header (x64)
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Malicious
4
19
32
46
65
78
90
[Base64-Block@0x00714AF4]
[Base64-Block-Decoded]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 3secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>pe:exe>scr:ps1~T1027~T1059.001~T1105
Shape pe:exe>pe:rsrc>pe:exe>scr:ps1
malicious 4 nodes
Path pe:exe>pe:rsrc>pe:exe
Shape pe:exe>pe:rsrc>pe:exe
3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
CODE
DATA
BSS
.idata
.tls
.rdata
.reloc
.rsrc
Resources
Malicious
RT_RCDATA
Malicious
ID:0000
Malicious
ID:0
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
.rdata
.data
.idata
.symtab
Optional Header (x64)
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Malicious
4
19
32
46
65
78
90
[Base64-Block@0x00714AF4]
[Base64-Block-Decoded]
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
41778c82d112b01f2ced7bd96b19da63 › Resources › RT_RCDATA › ID:0000 › ID:0 › .Net Resources › script.ps1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙