Malicious
Malicious

1d75df9619d0fd5be6bf10d2a72f0f01

ZIP Archive
MD5: 1d75df9619d0fd5be6bf10d2a72f0f01
Size: 672 B
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1d75df9619d0fd5be6bf10d2a72f0f01
Sha1 5ca6f136fba55a10a691a9b82eb6a0d56d863244
Sha256 bec11cab73d5b10e77bf5a019b61b076464e86751f35c351aa0af884e033dc7c
Sha384 076ee55f744954d9563a262d9c5f0a11051ad2da8ae3f3b72427d02b6170e5fec6a002e6e5dbd64245d1429eb83d2c9c
Sha512 7c59ce4552363ffc6595f976ccb6a9fd307e322db6dc46a87c928bbc95c0350ec0bdcfa0a9aca2db4f1bd2dca0427be16aeaad2f3f252c2ac153b18ab85a3d70
SSDeep 12:5jszPRdR9oUu+ZPj71MEOh93iCc0OG3pX0nD2C/3L6HPRAYrJaS/:9sFdR9OuMZr3C05pED2C/3L6J3J
TLSH AF012382FB38D337D18DF070928F4A421D092ED90F1549550ADD5C687C54CC4CCF5584
1d75df9619d0fd5be6bf10d2a72f0f01
Malicious
2026-Financial-Statements.cmd
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
1d75df9619d0fd5be6bf10d2a72f0f01
Malicious
2026-Financial-Statements.cmd
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
1d75df9619d0fd5be6bf10d2a72f0f01 › 2026-Financial-Statements.cmd › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
1d75df9619d0fd5be6bf10d2a72f0f01 › 2026-Financial-Statements.cmd › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙