Malicious
67ee6305e9d1017148aa909f0c29391c
PowerShell
MD5: 67ee6305e9d1017148aa909f0c29391c
Size: 2.84 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 67ee6305e9d1017148aa909f0c29391c |
| Sha1 | 6ccdb0ff83e263a254dadbd4fc6547470bec5377 |
| Sha256 | 74fd0bb45d835e60419dfac50d2fb2361b694b37d0d397b735880a39baddadaa |
| Sha384 | 50d3e505d289cbccc23921b37534ccf807264612272216230ea9c750f3deeae15276ec1546f62dc1f383e7ad0c898a96 |
| Sha512 | 27619dce447c3c294c22e037f8cd86efff114b21f4890164f52d9e638847e7c3912c0ae8c3b01caaec471aa64092bf483b1a4e7d12fc50afed66f22555570841 |
| SSDeep | 48:X8aKmMP0U9iOShs+81UbHLwfn/21G4i/e1n/ua3BU2CpKgb:XpMP0U9iOKs+81mLwf/21G4i/E/u++57 |
| TLSH | 1351124B7D0AC13A943A8F635EABF41DD9F0165B5109DC21B89C84462F323ECFBD21A9 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:ps1>scr:vbs>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" & hthuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c
Deobfuscated PowerShell
UNKNWOWNmalicious
" & hthuhuhuhuhuhuhuhuhuhuhu
67ee6305e9d1017148aa909f0c29391c › 67ee6305e9d1017148aa909f0c29391c.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.