Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 acce8788e1f12571ed0b85bd329515c3
Sha1 51b301c0bf99af48afae07426837e7d7f7536dba
Sha256 bf44090998d03a3a2764a620dfd2e6a3cfaefb5a9570fac1bb70cab1d0f0a257
Sha384 56fd5fcb49a2dc19901075bab00b679fb6a054f3638a5e261ead101691d41f23b22a49a94bc339d37176fce8eab3aac3
Sha512 1b8050c830a26e22ba51c04b580ba8296b9f3015cf3f47eb130c5ce02c7c53a7ab7353dcd64676cb32f0c3b111f63914079bfa2797344b29c1376ccbfbfd7dd1
SSDeep 196608:QbapblOOJKWl3FS2TjN2qaxbe4Zx2iXz/ntmvFhyjmHk:QbaPOzWl9TJEBjZx2MtCyaHk
TLSH 166633FE96011CAEC22F6972E5C5216FC1F0792D44FCD0DA16474BA89622EDD6A38D33
windows
Malicious
AccountUI.ps1
AccountView.xaml
BackupView.xaml
CHECK_LAYOUT.cmd
Malicious
[PowerShell Command]
Malicious
CHECK_PACKAGE.cmd
[PowerShell Command]
Malicious
DirectStorage.ps1
HistoryPolicy.ps1
INTEGRATED_README.txt
MISSED_BACKUP.ps1
PHONE_AUTOFIND_README.txt
README.md
SCHEDULED_BACKUP.ps1
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
START_INTEGRATED.bat
START_PHONE_AUTOFIND.cmd
Malicious
[PowerShell Command]
Malicious
START_UI.bat
START_WIFI_QR.cmd
START_WINFORMS.bat
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
TEST_V70_FIXES.cmd
TEST_WIFI_PC.cmd
TrialPolicy.ps1
내백업.hta
assets
cloud-friend.png
cloud-friend.png
0x00000131.svg
0x00000131.svg-preview.jpg
cloud-friend.png-preview.png
connection.png
connection.png-preview.png
laptop.png
laptop.png-preview.png
mybackup-icon.ico
mybackup-icon.png
mybackup-icon.png-preview.png
phone.png
phone.png-preview.png
license
issuer-public.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
wifi
account_policy.py
direct_storage.py
idle_policy.py
pc_pair_server.py
pc_pair_server.py
0x00004C16.svg
0x00004C16.svg-preview.jpg
pc_preflight.py
README.md
requirements.txt
transfer.py
trial_policy.py
tests
test_pair_server.py
test_transfer.py
test_v56.py
test_v57.py
test_v59.py
test_v60.py
test_v66.py
test_v68.py
test_v69.py
test_v70.py
test_v71.py
vendor
QRCODE_LICENSE.txt
qrcode
console_scripts.py
constants.py
exceptions.py
release.py
__init__.py
compat
__init__.py
image
styledpil.py
styles
colormasks.py
moduledrawers
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
release-manifest.json
README.txt
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 15 STICH kept: 9secondary ignored: 6
bin 3img 3

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path arc:zip>scr:ps1~T1027~T1059~T1059.001~T1059.005>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1>scr:vbs>scr:ps1
malicious 4 nodes
Path arc:zip>scr:ps1~T1027~T1059~T1059.005>scr:vbs~T1059.005
Shape arc:zip>scr:ps1>scr:vbs
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #1 UNKNWOWNmalicious
notepahuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
echo. huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
optionhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"' Deohuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" Deobhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
deobfuhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
windows
Malicious
AccountUI.ps1
AccountView.xaml
BackupView.xaml
CHECK_LAYOUT.cmd
Malicious
[PowerShell Command]
Malicious
CHECK_PACKAGE.cmd
[PowerShell Command]
Malicious
DirectStorage.ps1
HistoryPolicy.ps1
INTEGRATED_README.txt
MISSED_BACKUP.ps1
PHONE_AUTOFIND_README.txt
README.md
SCHEDULED_BACKUP.ps1
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
START_INTEGRATED.bat
START_PHONE_AUTOFIND.cmd
Malicious
[PowerShell Command]
Malicious
START_UI.bat
START_WIFI_QR.cmd
START_WINFORMS.bat
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
TEST_V70_FIXES.cmd
TEST_WIFI_PC.cmd
TrialPolicy.ps1
내백업.hta
assets
cloud-friend.png
cloud-friend.png
0x00000131.svg
0x00000131.svg-preview.jpg
cloud-friend.png-preview.png
connection.png
connection.png-preview.png
laptop.png
laptop.png-preview.png
mybackup-icon.ico
mybackup-icon.png
mybackup-icon.png-preview.png
phone.png
phone.png-preview.png
license
issuer-public.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
wifi
account_policy.py
direct_storage.py
idle_policy.py
pc_pair_server.py
pc_pair_server.py
0x00004C16.svg
0x00004C16.svg-preview.jpg
pc_preflight.py
README.md
requirements.txt
transfer.py
trial_policy.py
tests
test_pair_server.py
test_transfer.py
test_v56.py
test_v57.py
test_v59.py
test_v60.py
test_v66.py
test_v68.py
test_v69.py
test_v70.py
test_v71.py
vendor
QRCODE_LICENSE.txt
qrcode
console_scripts.py
constants.py
exceptions.py
release.py
__init__.py
compat
__init__.py
image
styledpil.py
styles
colormasks.py
moduledrawers
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
release-manifest.json
README.txt
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › AccountPolicy.ps1
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › LAUNCH_APP.ps1
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › LAUNCH_APP.ps1 › [Deobfuscated PS]
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › RUN_HIDDEN.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
$Errorhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › LAUNCH_APP.ps1 › [Deobfuscated PS] › [Deobfuscated PS]
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › START_APP.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › START_WPF_WIFI.cmd › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › START_PHONE_AUTOFIND.cmd › [PowerShell Command]
Command (COM trace) #1 UNKNWOWNmalicious
notepahuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs
Deobfuscated PowerShell UNKNWOWNmalicious
echo. huhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › TEST_LAPTOP.cmd › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
optionhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"' Deohuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs › 내백업_실행.vbs.deobfuscated.vbs › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
" Deobhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs › 내백업_실행.vbs.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
deobfuhuhuhuhuhuhuhuhuhuhuhu
acce8788e1f12571ed0b85bd329515c3 › windows › 내백업_실행.vbs › 내백업_실행.vbs.deobfuscated.vbs › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙