Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b78800cbda5d7e0a2bb33980abc65f34
Sha1 a7c3a3696bebec14256a842e14777c979a6a2c21
Sha256 fa76b2af590fa1fcc46ca38ec83ef40aa02616021bb88fb35106504342b3ac20
Sha384 7fa91e3e9f84f67faeea3c608ab3efebc40ce0e4a6342069df0c47add754681a09b4ad3a276e490c003bd48975b3c85e
Sha512 4fbe1af36e9be0e785b902b8845456708aacdc83ee18e22fcf1c1f31e1f5a3dbe362994f60ed9a2aea6c9ccbcbce50c8806e3fa6ccb6146ea9833ddf570f489b
SSDeep 24:9Uxz63kooBAuNlBrDTN4yU4aM0pwWPD8qXzhWoRFRGCKJ/zyRvezx0:9S63kJC6BrN4k01Thh+zAezm
TLSH 1E21E42C8A499046C83AF332A002F3C99ACDC652F009FE323F1EA6C204995C8A30380B
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbs~T1027~T1059.005~T1105
Shape arc:zip>scr:vbs
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
b78800cbda5d7e0a2bb33980abc65f34 › Document.vbs
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
b78800cbda5d7e0a2bb33980abc65f34 › Document.vbs
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
b78800cbda5d7e0a2bb33980abc65f34 › Document.vbs
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙