Malicious
4100b976150cb4015e1856d875637861
ZIP Archive
MD5: 4100b976150cb4015e1856d875637861
Size: 6.75 MB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4100b976150cb4015e1856d875637861 |
| Sha1 | ddee4ee51bf954bafd69256fa47f0a8e2ea2551c |
| Sha256 | b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636 |
| Sha384 | 217317e1971f0bb523b579ed9249df36709e39a13d2b3db5c7649f0c988907fcafb0ac6f439e21f4dbc0d109fcbf7449 |
| Sha512 | 8a457247fd33f0978a79e09f8fd42176991f0e9ccd62fe8ed84e224fec8da2c8f5aa8c7395cad5f4aead0f9590a4eb8ba0a90bdc0193baf920f027ccb35e2457 |
| SSDeep | 196608:zsLD6bmXv8UNTQxAHyksE4YHt2N0G0fJJPF:QCbmEhANsEpNOP2JJPF |
| TLSH | 0B66337FDFEAB6C2D937DB75842A1589AFF4C7AB32D47092242C449279CD1A2D8E0301 |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 6
STICH kept: 3secondary ignored: 3
img
2bin
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
arc:zip>scr:vbs~T1027~T1059~T1059.005~T1105
Shape
arc:zip>scr:vbs
malicious
2 nodes
Path
arc:zip>html>enc:b64
Shape
arc:zip>html>enc:b64
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › Docusign-Installer.vbs
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › Docusign-Installer.vbs
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › Docusign-Installer.vbs
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › Docusign-Installer.vbs
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › index.php
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4100b976150cb4015e1856d875637861 › dz-doc › dz-doc › Windows › download › index.php
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.