Malicious
5b81257b070e6b6643f571ed819a6b52
PowerShell
MD5: 5b81257b070e6b6643f571ed819a6b52
Size: 3.54 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 5b81257b070e6b6643f571ed819a6b52 |
| Sha1 | 8390a4659145d85ea58c150b115cd361962ab446 |
| Sha256 | 1dfd3e106ecb91b272c2c70b053de11afde937890a87b4f566e1cce615e96a52 |
| Sha384 | a25ac8e8c2f5e627762f221ecbad16fd947ead7ebbc4998452eaed30fc8e02732dcc23ee2fe98a179d085d5027bbb4f2 |
| Sha512 | f0041c5a9b58cc212675f1eb45d3aa2116455bae8641f07bcbccfe6ed363c64fa5e5cbc96da04e2dafc381c1dd50a7a0ac76c8d6ad64e8185cbf2f8bc355590c |
| SSDeep | 48:Zow667EovOOF7LeZaYh7yiRSEtlaxIZ3ajLVAU01Wol0/CsGdJCUT/eB/BhgcY7S:aw+oHinf9JZqjLVVol0/H6JhT/2/r1V |
| TLSH | B77101037707E1758CB18BB6C99FA809D5E02D576C0F08057DCD89D26F3539AB5E90A2 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:ps1>scr:vbs>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52 › 5b81257b070e6b6643f571ed819a6b52.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.