Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9bc11807516fddd62733db096809cb60
Sha1 ba84cf32e996fc009453a5ea9f11f40e619bc1b6
Sha256 a5828e4832274385b9645d39434e8038a31692ed6ba9948c4ec00e87c70097dd
Sha384 a378ee4592bbd0399a006c2dcc0cc497e878060acd426ff54e725950003b9e0fba03b6d86b4f62cc08fa8afa67da1952
Sha512 12ce65f353d16b09a0f9a265e3e8cceb4b7c26a6fc0b3555f3aeba0e17c22d3033279c2ab5e9e0fb351443523bc963e9829826737752e6de8b9f1d464152ce99
SSDeep 48:+5NlzNVh+n7CPJ2t8y/fUh8SawQLhKxrsaLIwcXeWWWAST:qpVYnGPJ2WIMuSawSK+aLIDN1jT
TLSH 5441B81FA50AE378857302A6A067AC4DCBD110671B318834BA9CCD8D2F343BDE7A7597
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(New-Ohuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
9bc11807516fddd62733db096809cb60
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
9bc11807516fddd62733db096809cb60
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
9bc11807516fddd62733db096809cb60
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
9bc11807516fddd62733db096809cb60 › 9bc11807516fddd62733db096809cb60.deobfuscated.vbs › [Command #2] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
(New-Ohuhuhuhuhuhuhuhuhuhuhu
9bc11807516fddd62733db096809cb60 › 9bc11807516fddd62733db096809cb60.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙