Malicious
Malicious

41a3ab94fa3291aba0b80eb1ce3415f0

Share on LinkedIn
Print
LNK File
MD5: 41a3ab94fa3291aba0b80eb1ce3415f0
Size: 75.94 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41a3ab94fa3291aba0b80eb1ce3415f0
Sha1 4980286e1e8599bedbfba2df72c5afc06d64c173
Sha256 a2c895dac1f192ecbafff199405e45cfffc5f033627890ab9b60ab5937be8cca
Sha384 4a431297e06ef912274779609faab64a6d572928a3b81ab42f7efdf09bfff0667ae9cab9b4358042f832ca12035ade45
Sha512 bcd9cddb76d3d47fb6357ed36140b895648dc65fd558f98a80ea96b4a2ee7f49f21bfee621476375449da7bf8a7c816c1799851b81e013621a7dac2d8f5af65f
SSDeep 1536:Lh1Sbek9mTe3gN5euBRfELJAhEfSqSVB5FgElq:94McgTZByLOKAVBntA
TLSH 8273F12059679111E0234EB8A93A6B06EC3EFD9DD967CB8C0514C1EC5AAADF05C93F7C
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk~T1027~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd~T1027~T1059.001~T1105>scr:ps1~T1027~T1059.001~T1105
Shape lnk>lnk:cmd>scr:ps1
malicious 3 nodes
Path lnk~T1027~T1059.001~T1059.003~T1202~T1204.002~T1218>scr:ps1~T1027~T1059.001~T1105
Shape lnk>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙