Malicious
ZIP Archive
MD5: 284783bce2882423de458e2989a502a9
Size: 10.07 MB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 284783bce2882423de458e2989a502a9 |
| Sha1 | 9d798150f8268f367c9aa7a2bf5a2dde07b0376e |
| Sha256 | 7e99e051cc6a925d1a860d36c332bf8095907823b6bddf5d21ae755e3568defc |
| Sha384 | 1f56b8c57523f79ba0db61f1dce16cdbe867e75f6717111ef94d6efb1c5ab45cc1a6179c7564623f4157a727f8898bb7 |
| Sha512 | 288d7bf740789e87fd1f75a838b9b910b0e9f4bfcc87c4e6893c57ee5dd925447df9f163c4e82ff8464a1e08fffeacf90b1e1869cc075812b79d670bc0c7b79d |
| SSDeep | 196608:TvbaGMlwmaLOPlYYmvkZj8FjZTHIjvkM21pa1WAy4Fk3ou7:Tv2xymaq9/mvkZjQdTHyp21QWAy73ou7 |
| TLSH | DCA63326F48B282DBBF7B3101A181D4F97F5615AB65A23768CC6097C8CEB77191A02C7 |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 6
STICH kept: 2secondary ignored: 4
bin
3img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape
arc:zip>scr:ps1
malicious
2 nodes
Path
arc:zip>pe:exe>enc:b64
Shape
arc:zip>pe:exe>enc:b64
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | http:huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
http:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential