Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5cbcc864374972d428b3f74f3aedb676
Sha1 7774b4c93f48bc59f1c810d2d2591c41c0db25e5
Sha256 2ab7812ca829f5e19e3fcd0a1b1ffd71d2d5b9f991af08d8013225ef09ae1140
Sha384 09992b2e75ca6c303b33197dc438c64d16372884e5074632863455d4c481fb9833a85f9a993bd4ef9dd3387a029207db
Sha512 cea90543be4c56308777cefb3bdb96429c5e27d8edd16fe88037f6fcc0d65d5cfd19c07bfa640a262e9999009f6a752ff985e071bcccc63d868743ac39327c80
SSDeep 24:XhUcuwF5URnas9AH5K37tKRz/MzQebr1XbM7b0JYGARt:XeXAZs7tKRMpi7GA/
TLSH B911509CAB0AD1322939838361B7DC4ED77248491C61F4AD7C60CC892D625F85F5D5EB
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
5cbcc864374972d428b3f74f3aedb676
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
5cbcc864374972d428b3f74f3aedb676
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
5cbcc864374972d428b3f74f3aedb676
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
5cbcc864374972d428b3f74f3aedb676
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙