Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 768e931c1483d9be625b20297cbbd20d
Sha1 33774bfd89f013cf1ab2aa6e3e7652a30adf09ca
Sha256 ed34f60ff0356c29bc8e54a3bda288a779c1f1f8479b42ca21df74dbaeccf113
Sha384 fad280503c3aaac389a457974b820354fdfa8fa0f2fcc2336bf70c814e3138ad57f6d894fd272c2077c5c98b5d4acdd9
Sha512 01a3bdba6f995e09b625bacff652f551e54d4e70944724da15637bad7f745bb350ab56d8e21edb8e7ac3ad298d053dd4595e8a336d485876a22109a71851578a
SSDeep 1536:kHdgtqKfekVIngO2Xh7syCDDRA8Ga+l56z:V9A52R7s7D5ol56z
TLSH 9053E101E9A414FCA9651A7EE06E4F3D4A263A970F54B45AF004C7E32E0CEBDD5B7217
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:bat>scr:ps1
malicious 3 nodes
Path scr:ps1~T1027~T1059~T1059.001~T1059.005>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"" Sehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"C:\Wihuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" " huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
768e931c1483d9be625b20297cbbd20d
Deobfuscated PowerShell UNKNWOWNmalicious
"" Sehuhuhuhuhuhuhuhuhuhuhu
768e931c1483d9be625b20297cbbd20d › 768e931c1483d9be625b20297cbbd20d.deobfuscated.vbs › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"C:\Wihuhuhuhuhuhuhuhuhuhuhu
768e931c1483d9be625b20297cbbd20d › 768e931c1483d9be625b20297cbbd20d.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" " huhuhuhuhuhuhuhuhuhuhu
768e931c1483d9be625b20297cbbd20d › 768e931c1483d9be625b20297cbbd20d.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙