Malicious
Malicious

a669645828361d431cb0f1c0ebbba5fd

JavaScript
MD5: a669645828361d431cb0f1c0ebbba5fd
Size: 2.18 MB
application/javascript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a669645828361d431cb0f1c0ebbba5fd
Sha1 c4ab53a134a2afa6874e79f55a834697528d8aad
Sha256 e8ee53d7067ef49252d133cf218c5df34c58bc17823e6857e9f3266818d8b097
Sha384 e3b47bbdc6121867af5fe9b8dd96f461e61be64630e6789b8e90de041fac34ef25a3d20f497639ddcd00932383cb684c
Sha512 0146ec9b781bcfb351a13c05eda3f7405dd952247bc417d7c6286f96389244c8d3de82fde2d8c3fc567c8f52e6c6901192740c0b27b5bdd27bb1ccfae6a051a1
SSDeep 384:Auuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu/uuuuuuuuuuuuuuuuuuuuuuuuuuuuu6:+pku
TLSH 4BA5E70232BFD70CF1F34E6C86E670946A77BB999A75C7D801B0184E05E5C90CAA2F67
a669645828361d431cb0f1c0ebbba5fd
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:js~T1027~T1059.001~T1059.007~T1105>scr:ps1~T1027~T1059.001~T1105
Shape scr:js>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
a669645828361d431cb0f1c0ebbba5fd
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
a669645828361d431cb0f1c0ebbba5fd
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
a669645828361d431cb0f1c0ebbba5fd
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
a669645828361d431cb0f1c0ebbba5fd
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
a669645828361d431cb0f1c0ebbba5fd
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙