Malicious
6da6c9137bc4a504aec88893759be856
PowerShell
MD5: 6da6c9137bc4a504aec88893759be856
Size: 3.56 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 6da6c9137bc4a504aec88893759be856 |
| Sha1 | 5fb7ec506d1e5c98449a81270ea437a273c88684 |
| Sha256 | 1fa2d2eacb3033959af5a59d5ba7aa6528e66af70922073bcad56ff42dbe9453 |
| Sha384 | 906183647c3df8391e0a6f8b0c47bf06957bb41a7d150d354c84f853b219f3efbb44aace4415b6e91ecb4b8bc8ac4870 |
| Sha512 | 8d53a641e5f56a21e8e63b78f45d9a894356e51a98cdd927d46046ae2854f3fa8bd11fcac42b1f29c3ae6447095db6b2c4cda48ae24e2babd8110aa0e6bff117 |
| SSDeep | 48:Zow667EovYyF7LeZaYh7yiRSEtlaxIZ3ajLVAU01Wol0/CsGdJCUT/eB/BhgcY7S:aw+ogyinf9JZqjLVVol0/H6JhT/2/r1V |
| TLSH | 057110037707E1758CB18BA6C99FA809E4E02D97AC0F08057DCC89D66F3539AB5F90A2 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:ps1>scr:vbs>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
6da6c9137bc4a504aec88893759be856 › 6da6c9137bc4a504aec88893759be856.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.