Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c5c2ae23fa34d045d6a887f9b3977eab
Sha1 378193e34a149670163752e629cea6855cfe78b8
Sha256 b902772635036ffdbc8f34877d923306ad1a66247fce31ca63fc0380c929542c
Sha384 d0807c5eb7b4f181f3a1d0aff036d7ec1a48518e36072a2d1275d1fe9806cfc253000274b7646058a139b147b10fc8f0
Sha512 5a99bfda6a1c307944dda02115609f45259108c821fa994496e978521c7b72b0c37977a1f86463f8fbca03404b04aef132d127057765f157d8e480724289d62b
SSDeep 24:8SPBAW9lKpqVD8FpHKnWWXtlAUW5+/CWPWe/CDCOPnSPoY4I0W4vQpK6+/CUPHqg:8SPDlxVDsWXtONTnsonItB6HitSq4WY
TLSH 22418C2427F90324E3BB8B7BACB6F31256367C50E9935BCE129056885828525E476F2F
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape lnk>lnk:cmd>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab › LNK CommandLine › [PowerShell Command]
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙