Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8604e0f263922501f749cfca447b041a
Sha1 85c712bdeaceb78e2785e1f63811b0c4a50f952d
Sha256 52ec3ba075a507e62bb6e3272fb13b30a8ddc0f62c4ea194311d558b338eb5ed
Sha384 9443225a5e9a7227ba330430c7118c54dac1d70b2eb6f9dfc0247d67bc84ec0a077523743b6228c298ab32bcbe3612ff
Sha512 496d7a1b8b55d28387dad3f1c43e164bb567259c4cac21dd632ccd450dfbf28d431330c27ea72a5a8034979c325d19ff3fd8a3f7fc12b1122f67ef595630d5b2
SSDeep 24:91mVy6UwvwrBg4o+xu9f2vyHwKmKuuuD5hioildx8R:91mOOwrBg8gUydU
TLSH EC114672D984B832E5C532B534078D428615A2C362B7D556C0EBD65A0D2B6436F83995
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbe>scr:vbs~T1027~T1059~T1059.005~T1105>scr:bat>scr:ps1~T1059.001
Shape arc:zip>scr:vbe>scr:vbs>scr:bat>scr:ps1
malicious 5 nodes
Path arc:zip>scr:vbe>scr:vbs~T1027~T1059~T1059.005~T1105>scr:bat>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:vbe>scr:vbs>scr:bat>scr:ps1
malicious 5 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(Writehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs
Command (COM trace) #2 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
(Writehuhuhuhuhuhuhuhuhuhuhu
8604e0f263922501f749cfca447b041a › info.vbe › info.vbe.decoded.vbs › info.vbe.decoded.vbs.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙