Malicious
2fc9f658c27f86e79a0137e91ea70da1
JavaScript
MD5: 2fc9f658c27f86e79a0137e91ea70da1
Size: 2.18 MB
application/javascript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 2fc9f658c27f86e79a0137e91ea70da1 |
| Sha1 | e9efaaa434a8293295efa649a97e3e04fe724b91 |
| Sha256 | afc85c1eaa5814d053d79fb4cc4dcad10aa53ca0e47950b8c33dcd7afb20ff02 |
| Sha384 | 8e87d719781860d4cb5cf92a42d35f43e7e2a5f4a5f5918dd554fb73c26c71b2750b2803249d89ad84c26001da8857e1 |
| Sha512 | 12a6dd3f388a53776f2a6f421cde240257d86665a0c464818d8daa9f02240750046a377e7ce96c0d6d184b1ab8f1f2d6918da21205418daf8972332a61984008 |
| SSDeep | 384:Auuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu/uuuuuuuuuuuuuuuuuuuuuuuuuuuuuN:+pkVT |
| TLSH | 28A5E70232BFD70CF1F34E6C86E670946A77BB999A75C7D801B0184E05E5C90CAA2F67 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:js~T1027~T1059.001~T1059.007~T1105>scr:ps1
Shape
scr:js>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #2
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
2fc9f658c27f86e79a0137e91ea70da1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.