Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6b457eed632aef2dc8c5f1792ec223b1
Sha1 7b339aca0518c934e04751b2be53f70d0c9e2802
Sha256 7583a696c82d66041cf8778d18c99ebc142dafde43f37fbe5dd088af6cad0fe8
Sha384 24fc02873d4be16a51e1f2599e170ab43f9070c1adb9d63943bd42a44ce570f7006b11fce3786193034134790155e2b6
Sha512 5e2b42e11f1f1239c2a26fda5a50542f89e3f3748b3ad82457d9ac3c90422ea04f3e4d55c1b72e732f4c2ea6d89bf4e4205e17265cd37e4d660370f549f89981
SSDeep 192:JoufXt4cGGRaGGHd43QBZilcR30pu4N59hHR6q47oqGbc7vQqF7+4+6/1/DO2KVj:Su11R1k6fx4WgzJF7jZDO2KZW/+8jI
TLSH 5083EDB110A6E6DBC319E037B23584196767E22842B7322738FE170D8B3FED6D6553A1
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059~T1059.005~T1105>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:ps1
malicious 2 nodes
Name Value
ISO
DiskImage extraction mode: DiscUtils (ISO)
Command (COM trace) #1 UNKNWOWNmalicious
wschuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"$Proghuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"" $Phuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Command (COM trace) #1 UNKNWOWNmalicious
wschuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1 › 6b457eed632aef2dc8c5f1792ec223b1 › .executed › .subscript.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
"$Proghuhuhuhuhuhuhuhuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1 › 6b457eed632aef2dc8c5f1792ec223b1.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"" $Phuhuhuhuhuhuhuhuhuhuhu
6b457eed632aef2dc8c5f1792ec223b1 › 6b457eed632aef2dc8c5f1792ec223b1 › .executed › .subscript.vbs › .subscript.vbs.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙