Malicious
Malicious

477bed44b725e0ece81eec2b61eb6786

ZIP Archive
MD5: 477bed44b725e0ece81eec2b61eb6786
Size: 2.37 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 477bed44b725e0ece81eec2b61eb6786
Sha1 944d9b4d8b1ccff2c49d119970b590385beeec49
Sha256 e54a6ca002f007042b9752091be95e28b27938663e581c65c895ed3e69a4b616
Sha384 ffb1b75318c9acf83f513a1c23d1f8d332bfcbc149d4ae81e5a8e9fc2059e297db15a47837aeea4ffa9bc617518eef79
Sha512 8d7d702c4ca132becb6ab6a0f0d7ac611e00f0ed09393155d1d969de3ad53a06d6d709a3300bd326a54dfc45114dc6f7ae4bb55ea044370366f36db124d8c03e
SSDeep 48:97oczd2aMKDDJdc0kqBLfJyy+48Ko6eHm5drhbV+rBaRdj:Fn8aZJ60lrb+/ZgvqAz
TLSH 9B41FB64DF89160DC155E7F7D5730D74DA89646B5606B73A59001222BF42F633F0F2C6
477bed44b725e0ece81eec2b61eb6786
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
meetingschedule.ps1
Readme.txt
Zoom-Meeting-Installer.cmd
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
^ $prhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
477bed44b725e0ece81eec2b61eb6786
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
meetingschedule.ps1
Readme.txt
Zoom-Meeting-Installer.cmd
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
477bed44b725e0ece81eec2b61eb6786 › Zoom-Meeting-Installer.cmd › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
477bed44b725e0ece81eec2b61eb6786 › Zoom-Meeting-Installer.cmd › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
^ $prhuhuhuhuhuhuhuhuhuhuhu
477bed44b725e0ece81eec2b61eb6786 › Installer.bat › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙