Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 50025748d75a1e51b72412f3071b3998
Sha1 d137dd49e5c9c25a2672c4bc5069652d57f50fa6
Sha256 3f048238fc1de83239e641dce3e17a55a0ee7d04ddbb3544d7c49b47fc4315db
Sha384 92be8f9a3d81a7d7533ba2e1b1b4b4b3fc47eb8a5a47ff74d74d4d13c5b294f4c297961dce46105429183339fdb30460
Sha512 e25bb8edaabf898cb54c499f9755cc2c91e3a5e16324924d76cdd2e70797b7e29a147f9552cab50b7cc0cb220a6473ee33bfd399bd81e83745f0b6a958a767fb
SSDeep 192:yqbEn5nk/raj6d1EG942WU/6WUV9OdIyv4pMN/d7TS37uk:5diLiy43fS3Kk
TLSH 08554C79EB03D9B2F3EDA1EF3955043102E0543E5F3A68D2A6AB0A9D0112FCCE15567A
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
50025748d75a1e51b72412f3071b3998 › 50025748d75a1e51b72412f3071b3998.deobfuscated.vbs › [Command #1]
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
50025748d75a1e51b72412f3071b3998 › 50025748d75a1e51b72412f3071b3998.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
50025748d75a1e51b72412f3071b3998 › 50025748d75a1e51b72412f3071b3998.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙