Malicious
07f237960b144e9a29e3097e57e9f6d0
ZIP Archive
MD5: 07f237960b144e9a29e3097e57e9f6d0
Size: 246.12 KB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 07f237960b144e9a29e3097e57e9f6d0 |
| Sha1 | 3859076b0e0279ea4af70d5277d6edd74ce3800b |
| Sha256 | d3b067ae9c10194df86de21ee5ba3d77b94e8529808c2fe025ddd7f2bbf0487c |
| Sha384 | 91699d38cc4feba2fdd48a0974c06b449ffd7af4346d268a69579d8f721d244da26c798ca173105da9f39c5b12b32098 |
| Sha512 | 3ada1634cfd79dcb5dbeeb54855853ea67beb248633f424a028f292aec2859786e88f8dbdadf1d4fde50534a70423e7fd660b0d66734a8c4d653ce3c0122d084 |
| SSDeep | 6144:s1YxGGhYtP9C3Bj+UwxPWC9E9YJATn93k7AsM:s1A1ePYj3YnSn93kEsM |
| TLSH | FE34237BF74B0567AC0942F1DB589C3F803AC1A9F442D247AD2ED4E787816EDA6F8406 |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 4
STICH kept: 1secondary ignored: 3
bin
3Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape
arc:zip>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhu
07f237960b144e9a29e3097e57e9f6d0 › Leeme.txt › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.