Malicious
Malicious

5b81257b070e6b6643f571ed819a6b52

PowerShell
MD5: 5b81257b070e6b6643f571ed819a6b52
Size: 3.54 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5b81257b070e6b6643f571ed819a6b52
Sha1 8390a4659145d85ea58c150b115cd361962ab446
Sha256 1dfd3e106ecb91b272c2c70b053de11afde937890a87b4f566e1cce615e96a52
Sha384 a25ac8e8c2f5e627762f221ecbad16fd947ead7ebbc4998452eaed30fc8e02732dcc23ee2fe98a179d085d5027bbb4f2
Sha512 f0041c5a9b58cc212675f1eb45d3aa2116455bae8641f07bcbccfe6ed363c64fa5e5cbc96da04e2dafc381c1dd50a7a0ac76c8d6ad64e8185cbf2f8bc355590c
SSDeep 48:Zow667EovOOF7LeZaYh7yiRSEtlaxIZ3ajLVAU01Wol0/CsGdJCUT/eB/BhgcY7S:aw+oHinf9JZqjLVVol0/H6JhT/2/r1V
TLSH B77101037707E1758CB18BB6C99FA809D5E02D576C0F08057DCD89D26F3539AB5E90A2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
5b81257b070e6b6643f571ed819a6b52 › 5b81257b070e6b6643f571ed819a6b52.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙