Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 5dd6d5c2a5f03fa2f5688f3d6114ec73
Sha1 31096a70fe860ee1a60b3a2b0aa6cfb9651e2c58
Sha256 4291caf2406a2efbf1fab6d62d3491eacf05e8399dff5e52e82e1a31a1208574
Sha384 11806a8c8b7007e190b80cb8bfbbc7ce8409f99ad8e41c36498fa74a715a7acf1bd6abdc33b8b40990d76c592a9fa5c6
Sha512 3ecedb75b42cfd43a9d850f2d4b804ec3e583f7cee3032ca27afabbc08d9dafb933590cff4e650a8233f5ef17ceb20d4794ea9785ab1e8324fc75a2bf1b75ab3
SSDeep 768:8OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOwwwwwwwwwwwwwwwwwwwwwwwwwwwwR:i
TLSH 52C339A0ED942A13FF860CFEF958BDCC7F57004D051A6096AB20EF52BAF10D1762BA55
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059~T1059.005~T1105
Shape scr:vbs
malicious 1 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
URL (COM trace) #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
URL (COM trace) #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Command (COM trace) #2 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5dd6d5c2a5f03fa2f5688f3d6114ec73
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙