Malicious
Malicious
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dc8f595456e314aff3efceb55f72f74f
Sha1 e02d982f78d80925324a2c72dde90a365dad8371
Sha256 b7330cf42457ba3a1cb515d260f2fb3f4dd90e4de9cf26fd6b070cf53109df6d
Sha384 bd8b0bc53680eb820da50e53f74e457049bc580097d91b503fa16c324157a3284e8c7e64dde4c3a9d8d0deede7f93741
Sha512 00bc5ca618efd4fb6109b3207e1aabd750a7ac0a805d05e4e5f085d8e1fd0da67422cb599142c397dbab5842d9f35948dde20cd9b7675bead6d5caf10e17b100
SSDeep 24576:t/sffqbNv51KUiAsO4sKps6CT28TSo3pLCym7hpxZU9xfARdKVKm32XsEdfQAxD7:drBI
TLSH 61269F606E5859F5EF8C6A0E90AE6F1D87F042176A33706BFB41DF04BD9A341864B21F
[Base64-Block]
dc8f595456e314aff3efceb55f72f74f.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path scr:vbs~T1027~T1059.001~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Path scr:vbs~T1027~T1059.001~T1059.005>scr:ps1~T1027~T1059.001~T1059.005>scr:vbs~T1059.005
Shape scr:vbs>scr:ps1>scr:vbs
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
bypasshuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b64 =huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Base64-Block]
dc8f595456e314aff3efceb55f72f74f.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
dc8f595456e314aff3efceb55f72f74f › dc8f595456e314aff3efceb55f72f74f.deobfuscated.vbs › [Command #0]
Deobfuscated PowerShell UNKNWOWNmalicious
bypasshuhuhuhuhuhuhuhuhuhuhu
dc8f595456e314aff3efceb55f72f74f › dc8f595456e314aff3efceb55f72f74f.deobfuscated.vbs › [Command #0] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
$b64 =huhuhuhuhuhuhuhuhuhuhu
dc8f595456e314aff3efceb55f72f74f › dc8f595456e314aff3efceb55f72f74f.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙