Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4ae6397d898c18b1356dedcbe225e639
Sha1 8ddc91dd3c92113e654815c91c9accde8170dde1
Sha256 83554baeeb700815f9b6492584a1b1a40c64f752d1ff1a67cde079ad524b008f
Sha384 610c381f2c30fb9b7d68bdd5bea6937961d4dfe91c2641308fafc92c79d7fcc78f0d0d5d492d16bb04da2ce9364a5fa6
Sha512 61a02edb4dd147e63ec7adea49d75e6adf7c6384134d8b833006cde6eaba60c2c3a89b32ab8c1afe0bfd39a96d4480a860bb4333c58943592f58670c4febe5ca
SSDeep 393216:WBuh88jMY2LToqSLIGug8C+U1C39YGOFEEV6DnyPQTKH1OZVozeXo80BkpiQv8v:WSwYOOvu/CmY1FE1jWQTY5C0mRvE
TLSH 692733289FEDE638C19647B6C7945A34CDA908C911DC7277934D2F13EEC3A2A507B1B8
PeID
Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
[NSIS Installer] @ #0000FE08
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
dummy_padding.dat
file1_info.json
8b1TxWhUQt5V.part5678
KOlY9urxpB0y.part5678
XuiRVO7rS5wo.part5678
hooxKyEvCw8C.part5678
[SETUP_DECOMPILED.NSI]
Overlay_4c91aeac.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 5secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape pe:exe>scr:vbs>scr:bat>scr:ps1
malicious 4 nodes
Path pe:exe>scr:vbs~T1027~T1059.005>scr:bat
Shape pe:exe>scr:vbs>scr:bat
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_4c91aeac.bin (22010075 bytes)
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" varhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"" huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" varhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"" [Uhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
& [Unmhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[NSIS Installer] @ #0000FE08
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
dummy_padding.dat
file1_info.json
8b1TxWhUQt5V.part5678
KOlY9urxpB0y.part5678
XuiRVO7rS5wo.part5678
hooxKyEvCw8C.part5678
[SETUP_DECOMPILED.NSI]
Overlay_4c91aeac.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › QaoZ1i5FUxKj.part5678
Deobfuscated PowerShell UNKNWOWNmalicious
" varhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"" huhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" varhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"" [Uhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
& [Unmhuhuhuhuhuhuhuhuhuhuhu
4ae6397d898c18b1356dedcbe225e639 › [NSIS Installer] @ #0000FE08 › Setup.vbs › Setup.vbs.deobfuscated.vbs › [Command #2] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙