Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ae5ae7829e21ae0e9fbf4b7c62531417
Sha1 970b364f63dfa99692e2a829f732d5159b7ada77
Sha256 d6a5ec91bf15db1764e679ad0c72e83231c4558df1b670435db983c387183cab
Sha384 b4b5e0ce75d885d7a0e3ab938e11ccb3366a05a3bd530f1db2b459b993acb88a782f5213eff23c988dd1c05a5686f01a
Sha512 597140344fa232f7caa55102575c3d0e4914630ecc0c25a5becd2056370e984885c5df070d9fb7ced314f37f3bd20647a2ff32f55c4507fe6fdf703c5021feaf
SSDeep 192:g+Sydu0/9do26pC7cDYF7HL1zU1/qVauF/f/7A/egUwbO4PgQC8:gzydVfo/pC41/SaMJ3wb/17
TLSH 2722B463120BE2F2C0F261072677A50EFA41B57755F2B439BDDC4400DF61B5993DA8DA
ae5ae7829e21ae0e9fbf4b7c62531417.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1047~T1059~T1059.001~T1059.005~T1105>scr:bat~T1059.001~T1105>scr:ps1~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #2 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
ae5ae7829e21ae0e9fbf4b7c62531417.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI & huhuhuhu
Payload Destination & huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Dropped path (COM trace) #2 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ae5ae7829e21ae0e9fbf4b7c62531417
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙