Malicious
5e83b5c0a53dc653c8c8f1bb846b48f6
LNK File
MD5: 5e83b5c0a53dc653c8c8f1bb846b48f6
Size: 774.87 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 5e83b5c0a53dc653c8c8f1bb846b48f6 |
| Sha1 | ee859f08e8bccd4d0004534a709f20760c7dd292 |
| Sha256 | fc95c3f88a4007752428e95b6fa225491dcbce0cdd4daaa75aad542ed6186ebb |
| Sha384 | 98bf4e60b7b7eaa0fd6dd0edc8d54c4a12f928db24f2c9ddeb6da534fe5d49e06afe0bbb010964701213d23410ae4fb9 |
| Sha512 | 9930c249daacb21510efa97ff7591a5275af5be21f9ba841240d1d79cacd9ee363100d9b0a3b3a4a10b15a4c1d23b1cdbe1fbcbe9e125eec8766885b724ee5ff |
| SSDeep | 24:8d/QngRiqX+yDW9KT629p/BxU/n9IW5MZ/RrhwUDmI:8lQgQqXFDW9l0p/UFL5K/bX |
| TLSH | FFF4AFC125E81300F1B7FE3ADEBAAB40053BBA81DD32879C8960CC5C1564541DA39F37 |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
lnk~T1027~T1059.001~T1059.003~T1059.005~T1202~T1204.002>lnk:cmd>scr:ps1~T1027~T1059.001
Shape
lnk>lnk:cmd>scr:ps1
malicious
3 nodes
Path
lnk~T1027~T1059.001~T1059.003~T1059.005~T1202~T1204.002>scr:ps1~T1027~T1059.001
Shape
lnk>scr:ps1
malicious
2 nodes
LNK: Command Execution
UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
& Remohuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
& Remohuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
No malware configuration was found at this point.
LNK: Command Execution
UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
5e83b5c0a53dc653c8c8f1bb846b48f6
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
5e83b5c0a53dc653c8c8f1bb846b48f6 › [Lnk Summary]
Deobfuscated PowerShell
UNKNWOWNmalicious
& Remohuhuhuhuhuhuhuhuhuhuhu
5e83b5c0a53dc653c8c8f1bb846b48f6 › [Lnk Summary] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
& Remohuhuhuhuhuhuhuhuhuhuhu
5e83b5c0a53dc653c8c8f1bb846b48f6 › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.