Malicious
Malicious

6da6c9137bc4a504aec88893759be856

PowerShell
MD5: 6da6c9137bc4a504aec88893759be856
Size: 3.56 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6da6c9137bc4a504aec88893759be856
Sha1 5fb7ec506d1e5c98449a81270ea437a273c88684
Sha256 1fa2d2eacb3033959af5a59d5ba7aa6528e66af70922073bcad56ff42dbe9453
Sha384 906183647c3df8391e0a6f8b0c47bf06957bb41a7d150d354c84f853b219f3efbb44aace4415b6e91ecb4b8bc8ac4870
Sha512 8d53a641e5f56a21e8e63b78f45d9a894356e51a98cdd927d46046ae2854f3fa8bd11fcac42b1f29c3ae6447095db6b2c4cda48ae24e2babd8110aa0e6bff117
SSDeep 48:Zow667EovYyF7LeZaYh7yiRSEtlaxIZ3ajLVAU01Wol0/CsGdJCUT/eB/BhgcY7S:aw+ogyinf9JZqjLVVol0/H6JhT/2/r1V
TLSH 057110037707E1758CB18BA6C99FA809E4E02D97AC0F08057DCC89D66F3539AB5F90A2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856 › 6da6c9137bc4a504aec88893759be856.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙