Malicious
b6562ac5a4f7885c1a995999336cd3aa
ZIP Archive
MD5: b6562ac5a4f7885c1a995999336cd3aa
Size: 105.25 KB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b6562ac5a4f7885c1a995999336cd3aa |
| Sha1 | 61670f724cd74cfe29384502050b50dc6da369e0 |
| Sha256 | ea6a0df56f91552d3030b0a3db6358fbe83e92895e7bf58188f34efa5e1093a5 |
| Sha384 | 9dc154a5d3e20c34b36de549f4532cb2a573777c501679fe3dd4235b98dea122158eb3651d44a730b605e21a8c6e8788 |
| Sha512 | 762e3753b0c4890526e101bad422615f40a48695db16f50b62b2199f417e0a99c35a0e98f0310a56fa78e67f4cc88656c2058f3e96df6507f7a7a42afe08a937 |
| SSDeep | 1536:TC0I5lsjvpexIKqNVQFc2DT6E//F39CLA9ylvat1snH9gPSsfB3oSIcilBNy:u0Sl2v66V+T6utCL9CtOH9+SaVITfNy |
| TLSH | 33A312E563FEAC7DD673308D8563152C3900A0E704AE2BADB53882C955B9B47D82C29F |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 1secondary ignored: 2
bin
1img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
arc:zip>pe:exe>scr:ps1~T1059.001~T1105
Shape
arc:zip>pe:exe>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b6562ac5a4f7885c1a995999336cd3aa › ArabProgrammerLibrary.exe › .Net Resources › Start-Library.ps1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.