Malicious
Malicious

477bed44b725e0ece81eec2b61eb6786

Share on LinkedIn
Print
ZIP Archive
MD5: 477bed44b725e0ece81eec2b61eb6786
Size: 2.37 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 477bed44b725e0ece81eec2b61eb6786
Sha1 944d9b4d8b1ccff2c49d119970b590385beeec49
Sha256 e54a6ca002f007042b9752091be95e28b27938663e581c65c895ed3e69a4b616
Sha384 ffb1b75318c9acf83f513a1c23d1f8d332bfcbc149d4ae81e5a8e9fc2059e297db15a47837aeea4ffa9bc617518eef79
Sha512 8d7d702c4ca132becb6ab6a0f0d7ac611e00f0ed09393155d1d969de3ad53a06d6d709a3300bd326a54dfc45114dc6f7ae4bb55ea044370366f36db124d8c03e
SSDeep 48:97oczd2aMKDDJdc0kqBLfJyy+48Ko6eHm5drhbV+rBaRdj:Fn8aZJ60lrb+/ZgvqAz
TLSH 9B41FB64DF89160DC155E7F7D5730D74DA89646B5606B73A59001222BF42F633F0F2C6
477bed44b725e0ece81eec2b61eb6786
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
meetingschedule.ps1
Readme.txt
Zoom-Meeting-Installer.cmd
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
^ $prhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙