Malicious
Malicious

a68b0c9a79099841e8b63bd6b61552c9

ZIP Archive
MD5: a68b0c9a79099841e8b63bd6b61552c9
Size: 8.16 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a68b0c9a79099841e8b63bd6b61552c9
Sha1 2c983d9d3aec5d9512a0529da89a37753c00d81e
Sha256 bc4512078b993c130848ffbffda663c444f1a299cfb56d177bed9cd2f63742cb
Sha384 52fc8c8a85e1e862087ccd760e08b9207c1d431ab14fe1ca929a3d21a58459ed0a60b67417ad66abe16ca7ceaea21133
Sha512 a8a857b5bbc21727ee5ecbf07dba3f8bc21befd1cd3cf53dd57de510f0c87d047949fe57d7baca700a0b27926aacda4a315eb6b19ac628b89af36fcec6429af8
SSDeep 96:X25dcZCNpfTZYPJgBf1asrC6/AWdJoNb40D5FX:X28Z0Vh0srC49Jr8l
TLSH D1F150BEA47B02F8C7CDC8B145981BC3037A8B747D85BAA5A9BD7C48BE450D48848D5F
78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js
Malicious
78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbs~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:vbs>scr:bat>scr:ps1
malicious 4 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js
Malicious
78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js.deobfuscated.vbs
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
a68b0c9a79099841e8b63bd6b61552c9 › 78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js › 78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js.deobfuscated.vbs › [Command #0]
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
a68b0c9a79099841e8b63bd6b61552c9 › 78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js › 78ea909c08497ac448e2e337ea2e9793c81147edd2eecd42b4c1fa77fd1c52b8.js.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙