Malicious
ZIP Archive
MD5: 3a243fe8d6d02416e33d62248c25f40f
Size: 11.76 MB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 3a243fe8d6d02416e33d62248c25f40f |
| Sha1 | ffeeb2530a4c9f498cb96d5494e0ab2480a63a13 |
| Sha256 | d89ba5767848eb5597d03a1d0ae30cc451050859fbc3b9fd3095a9474dd7d86b |
| Sha384 | 347737d23e0301a2992a1ea90263eae55c213066fd34a5d84dee64eaf2237c970fb9c8eb606a8823a607945023ccdcbe |
| Sha512 | 87b1adc26d52695840ed272a0cc90782fbc08cafebeeb51c1fa89769e4802942af91853abf1b75222e876a6e3533b6462212865dae1c82b70ff5a8c759f01380 |
| SSDeep | 196608:v8vC7ouppwWscp1H+Fg0eMldZUsqoZVtPz6E+DMl0SkULeCclszL5:v8yokwWsc7HCSsRXDtPz6TDa0HULenly |
| TLSH | 3FC633508E3C5EFFD94BF33B20E9859B692D8B023443766F3D2E61939C472D16B09A19 |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 5secondary ignored: 7
bin
6img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
5 / 5
Path
arc:zip>scr:ps1~T1059.001~T1105
Shape
arc:zip>scr:ps1
malicious
2 nodes
Path
arc:zip>arc:zip>scr:vbs~T1059.005
Shape
arc:zip>arc:zip>scr:vbs
technique3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential