Malicious
Malicious

67ee6305e9d1017148aa909f0c29391c

PowerShell
MD5: 67ee6305e9d1017148aa909f0c29391c
Size: 2.84 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 67ee6305e9d1017148aa909f0c29391c
Sha1 6ccdb0ff83e263a254dadbd4fc6547470bec5377
Sha256 74fd0bb45d835e60419dfac50d2fb2361b694b37d0d397b735880a39baddadaa
Sha384 50d3e505d289cbccc23921b37534ccf807264612272216230ea9c750f3deeae15276ec1546f62dc1f383e7ad0c898a96
Sha512 27619dce447c3c294c22e037f8cd86efff114b21f4890164f52d9e638847e7c3912c0ae8c3b01caaec471aa64092bf483b1a4e7d12fc50afed66f22555570841
SSDeep 48:X8aKmMP0U9iOShs+81UbHLwfn/21G4i/e1n/ua3BU2CpKgb:XpMP0U9iOKs+81mLwf/21G4i/E/u++57
TLSH 1351124B7D0AC13A943A8F635EABF41DD9F0165B5109DC21B89C84462F323ECFBD21A9
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & hthuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c
Deobfuscated PowerShell UNKNWOWNmalicious
" & hthuhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c › 67ee6305e9d1017148aa909f0c29391c.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙