Malicious
7z-stream @ 0x00000000.7z
7Zip Archive
MD5: 278efe9fed78275e61c9642301730f3b
Size: 1.02 MB
application/x-7z-compressed
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 278efe9fed78275e61c9642301730f3b |
| Sha1 | da235469d36f180bdc956e69f86a56606212c466 |
| Sha256 | 552fec551719f12507dfd582dd5e8176134d9267f45847eb5f8941d864629d78 |
| Sha384 | 1778b093558a93467e7d862e2c8900123a86e8d8c0c2d355fa3afe6ef6de4c23ad03ab50d3be410480b83f8f932f7e8f |
| Sha512 | 40021a75f76e069c0c90d81ff43c84b31cc300f22843962ace28e77c1f45f6bbfaa38187518306a7ded987c78b550b01cbcaefc9f98ed2032b02f372e4b2b295 |
| SSDeep | 24576:9uxpcVW7TtImbwkZIUgYOAXXwt8zXDtBT5P:9u/KAamBIUlOAXAtuHT5P |
| TLSH | B82523F1DD1BEE01FCD29ABB32C1853B38196049226ABE8A745691D24E93FD3F53E114 |
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 7
STICH kept: 6secondary ignored: 1
bin
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
6 / 6
Path
arc:7z>html~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape
arc:7z>html>scr:bat>scr:ps1
malicious
4 nodes
Path
arc:7z>html~T1027~T1059~T1059.005>scr:vbs~T1059.005>enc:b64
Shape
arc:7z>html>scr:vbs>enc:b64
malicious
4 nodes
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
(if "huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
Unblochuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #1
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
No malware configuration was found at this point.
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › thumbnail.hta
Deobfuscated PowerShell
UNKNWOWNmalicious
(if "huhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › payload.hta › payload.hta.deobfuscated.vbs › [Command #2] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › payload.hta › payload.hta.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
Unblochuhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › payload.hta › payload.hta.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Command (COM trace) #1
UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › payload.hta
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
278efe9fed78275e61c9642301730f3b › payload.hta
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.