Malicious
Malicious

b6562ac5a4f7885c1a995999336cd3aa

ZIP Archive
MD5: b6562ac5a4f7885c1a995999336cd3aa
Size: 105.25 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b6562ac5a4f7885c1a995999336cd3aa
Sha1 61670f724cd74cfe29384502050b50dc6da369e0
Sha256 ea6a0df56f91552d3030b0a3db6358fbe83e92895e7bf58188f34efa5e1093a5
Sha384 9dc154a5d3e20c34b36de549f4532cb2a573777c501679fe3dd4235b98dea122158eb3651d44a730b605e21a8c6e8788
Sha512 762e3753b0c4890526e101bad422615f40a48695db16f50b62b2199f417e0a99c35a0e98f0310a56fa78e67f4cc88656c2058f3e96df6507f7a7a42afe08a937
SSDeep 1536:TC0I5lsjvpexIKqNVQFc2DT6E//F39CLA9ylvat1snH9gPSsfB3oSIcilBNy:u0Sl2v66V+T6utCL9CtOH9+SaVITfNy
TLSH 33A312E563FEAC7DD673308D8563152C3900A0E704AE2BADB53882C955B9B47D82C29F
.Net Resources
Malicious
Start-Library.ps1
Malicious
[PowerShell Command]
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 1img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe>scr:ps1~T1059.001~T1105
Shape arc:zip>pe:exe>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
.Net Resources
Malicious
Start-Library.ps1
Malicious
[PowerShell Command]
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙