Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 43a39f7b705a9aa3bdbd06a3be6e763c
Sha1 6d24a68a33f56e05004239ffe9ccb5638e293bbb
Sha256 aa75725634e9d7c4004b625c3f5d216dbddaeeda06e1fa7308a28a87c60b5b23
Sha384 56d535c135cf6f1ca12534cf6c07ff98fe3aa23e5e031c2499081863d14ae93c827d8f93cfeb0a957b67b6b5bd68c2b7
Sha512 9aa7b89580cf01889037ad4b02877359dafeefe0b9e13687645d94f3ef660c0a2f90914982523a6ea5bcfa8ebabb6f50df031ec88e891dcdb2cd2aa5e514ecb7
SSDeep 48:TwoZH8qOi4LUnSWFqmIMV/MkLMVanxZ7+0O:TB58qOi4LW1kwzHxZ5O
TLSH A9317202E607DFF863929CF4B394391AA5F0C96B66051036D6CC8954770F9B53774A36
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1047~T1059~T1059.005~T1105
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
43a39f7b705a9aa3bdbd06a3be6e763c
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙