Malicious
Malicious

14201c51d9407b1b10e1c39eb3a349e4

Share on LinkedIn
Print
ZIP Archive
MD5: 14201c51d9407b1b10e1c39eb3a349e4
Size: 1.39 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 14201c51d9407b1b10e1c39eb3a349e4
Sha1 a7e95be7e2a5526814cfb91f44a4df3805781de6
Sha256 eaaa4bc79fde2741c391726f90fe393f63e0be136aa6a2eb7cb8c11e54e72c79
Sha384 ed7d205fe88bf945b40bad015c14079f84917a58e7cc74bc87548fc9b5794cb9a98b9350beb58f182ac74b83c502c11b
Sha512 ed12c35b11df9254ad1cdca46f2b53a222ad376ed42ccbc7f18e7ca2d0ab7e92deffadf790213eab1b2da4f3ec95f98628412fa3964642c12b083a3cf5553d57
SSDeep 24576:N+NvjCGtzG1Bw6wUp7Pv5R6q7Js+KWFWBXGOI3d7r2k4skIMWIGIteDqt/:NIWGCfwU1j67+KWmXGdd7r2k6nsS
TLSH 775533E0FDA1C1F1BCA781A3269B2840BC0178895B307D97B5BCC3D7137DA5D15AB6A2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 2secondary ignored: 1
img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>lnk~T1027~T1059.001~T1059.003~T1105~T1202~T1204.002~T1218>lnk:cmd~T1027~T1059.001~T1105>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>lnk>lnk:cmd>scr:ps1
malicious 4 nodes
Path arc:zip>lnk~T1027~T1059.001~T1059.003~T1105~T1202~T1204.002~T1218>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>lnk>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"$b=[Chuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
$b = [huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
start-huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙