Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9ebf0e1a54cdf15a4bcfcbfbdc12958f
Sha1 3b750cb6c9f401ec5780ae615552be53f879d373
Sha256 93a180ec5678568b9d071861338cc3572ac8c95cba3f7887ab597565c722602f
Sha384 9f84888f9d99a7e0036af3c53c5879267b76604272c924f60a62405ad5108776acfad685c7210e3d7460277696842dce
Sha512 93298eab5a66131378edafc1216e791292f0a3154c648b726b7d5a01da9d36fe4649db92c1803a9baeec5332afd6d7732a07517699e00bc45892b484dd820752
SSDeep 24576:UzyEQIEATJ9N2sO4sKps6CT28TSo3pLCym7hpxZU9xfARdKVKm32XsEdfQAxDKvV:TBn
TLSH 7B269F606E5859F5EF8C6A0E90AE6F1D87F042176A33706BFB41DF04BD9A341864B21F
[Base64-Block]
9ebf0e1a54cdf15a4bcfcbfbdc12958f.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001~T1059.005>scr:vbs~T1059.005
Shape scr:vbs>scr:ps1>scr:vbs
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
bypasshuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b64 =huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Base64-Block]
9ebf0e1a54cdf15a4bcfcbfbdc12958f.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
9ebf0e1a54cdf15a4bcfcbfbdc12958f › 9ebf0e1a54cdf15a4bcfcbfbdc12958f.deobfuscated.vbs › [Command #0]
Deobfuscated PowerShell UNKNWOWNmalicious
bypasshuhuhuhuhuhuhuhuhuhuhu
9ebf0e1a54cdf15a4bcfcbfbdc12958f › 9ebf0e1a54cdf15a4bcfcbfbdc12958f.deobfuscated.vbs › [Command #0] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
$b64 =huhuhuhuhuhuhuhuhuhuhu
9ebf0e1a54cdf15a4bcfcbfbdc12958f › 9ebf0e1a54cdf15a4bcfcbfbdc12958f.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙