Malicious
Malicious

2fc9f658c27f86e79a0137e91ea70da1

JavaScript
MD5: 2fc9f658c27f86e79a0137e91ea70da1
Size: 2.18 MB
application/javascript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2fc9f658c27f86e79a0137e91ea70da1
Sha1 e9efaaa434a8293295efa649a97e3e04fe724b91
Sha256 afc85c1eaa5814d053d79fb4cc4dcad10aa53ca0e47950b8c33dcd7afb20ff02
Sha384 8e87d719781860d4cb5cf92a42d35f43e7e2a5f4a5f5918dd554fb73c26c71b2750b2803249d89ad84c26001da8857e1
Sha512 12a6dd3f388a53776f2a6f421cde240257d86665a0c464818d8daa9f02240750046a377e7ce96c0d6d184b1ab8f1f2d6918da21205418daf8972332a61984008
SSDeep 384:Auuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu/uuuuuuuuuuuuuuuuuuuuuuuuuuuuuN:+pkVT
TLSH 28A5E70232BFD70CF1F34E6C86E670946A77BB999A75C7D801B0184E05E5C90CAA2F67
2fc9f658c27f86e79a0137e91ea70da1
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:js~T1027~T1059.001~T1059.007~T1105>scr:ps1
Shape scr:js>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
2fc9f658c27f86e79a0137e91ea70da1
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙