Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 591f0a61ae3446971e98c2d8b7e41d2f
Sha1 5adc02ebcc1c9265180d3e447f42eb6a5906f7fa
Sha256 7f3347e8ab745e8a9d4f49ea31fa574225783d3fd0fb89767236cd8e25ec6b5e
Sha384 6499f5d2e58f2a49f1b2105740cf4b267af00628cfe9c63b059f35df17b73e0230eadca3a0e9594b69200a55a9b02622
Sha512 82ba5479d1cac26c8a9a971e8e6f91b70bd9aa1dd23c892d8a1e7a8a7126b2bbd9b615c6f78a2cb9e935b76bc8919b839efbb1bf4a0369c773c40c15c7c1338d
SSDeep 384:3WjxpXJcrzW8r4cWLWZt74nWlDqq7WnZt74rWFrcpcCnWlIxpXJcrzW5tWerCcD8:hij0kJGFBSuZiOlaOMkOk86LeX
TLSH B7459422FAD414F46F517E1302771A44B89C17DBE638246BCA928874D9B78B0D2E7B73
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
591f0a61ae3446971e98c2d8b7e41d2f › 591f0a61ae3446971e98c2d8b7e41d2f.deobfuscated.vbs › [Command #1]
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
591f0a61ae3446971e98c2d8b7e41d2f › 591f0a61ae3446971e98c2d8b7e41d2f.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
Copy-Ihuhuhuhuhuhuhuhuhuhuhu
591f0a61ae3446971e98c2d8b7e41d2f › 591f0a61ae3446971e98c2d8b7e41d2f.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙