Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 75be66b006a76f3236331f193c6cc965
Sha1 3c1022c4c5b2bf256e940bd910b7b7bdc274c754
Sha256 760b0559219c1775d5213e020579ef6f37ee16ffa5a6d4827e8b66cc911d8974
Sha384 519838e324ffd2b2b8dc0dd443e36d50d557397c0924f3272026728c87b9867c67adb298f3887c76e0c382b1af347ff9
Sha512 06a42ee9b84619b6090935845788ff21026f80139d85501d24179e7ff33205ec866e908254b53dc771c4f39b2fbfdf251e6222d6cc766abb76b921d57234dc60
SSDeep 98304:wY3CGZQQDVzlSpHBJbevA8CzFcutydMD6ZzqBGBzcR28u0tx1wkmo0RR6fL:F3BDVzYpHeOzFc1d8ozqB040P0t+X6T
TLSH 2146338ED0D25C2F4E3DC1DE4AA29FA50741BCC15952B150726CA707B2EE3F2B7876A4
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path arc:rar>scr:ps1~T1027~T1059~T1059.001~T1059.005~T1112>scr:bat>scr:ps1~T1027~T1059.001
Shape arc:rar>scr:ps1>scr:bat>scr:ps1
malicious 4 nodes
Path arc:rar>scr:ps1~T1027~T1059~T1059.001~T1059.005~T1112>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape arc:rar>scr:ps1>scr:vbs>scr:ps1
malicious 4 nodes
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
timeouhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
timeouhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
75be66b006a76f3236331f193c6cc965 › GAME_PATCH_INSTALLER.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
timeouhuhuhuhuhuhuhuhuhuhuhu
75be66b006a76f3236331f193c6cc965 › GAME_PATCH_INSTALLER.vbs › GAME_PATCH_INSTALLER.vbs.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
timeouhuhuhuhuhuhuhuhuhuhuhu
75be66b006a76f3236331f193c6cc965 › GAME_PATCH_INSTALLER.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙