Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 57b7e50ba69937dcf02a636960f3794b
Sha1 ac7c01d513d2eccf84c1fa03dce9e736e0a961af
Sha256 02b3058057d9bd512199f9a350f02952bb5104950f3c5eb72d4c439fc6403665
Sha384 52c6e5daae2d26cdf2996c2dba545f4f71bb530ce22be295aa7401022a14bb3e850377e46c44be39df276f9c0e859cd4
Sha512 b92c9da9d3af7e8fd558e95ce9222aa78de65682909c51c8263810fb781f98754ea0d5dd7548487a737f4035438d0a4816701737e195a6bdc6e2e9f8f8e978d6
SSDeep 24:ixip3Mb/AG0bjKvOg5ZYM+BXcpNTETDDPz4vzUZuLIJUXNULWMCawYHVdR3HMGlq:iHYGL+Xc0fDLK59Ri/wZAc
TLSH 8E41C04FE20CDBD28CB23AE5D9C1C42AF9E13A2315451B54B52EA09CCFB7AC5D98D0D9
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b
Deobfuscated PowerShell UNKNWOWNmalicious
curl huhuhuhuhuhuhuhuhuhuhu
57b7e50ba69937dcf02a636960f3794b › 57b7e50ba69937dcf02a636960f3794b.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙