Malicious
Malicious

b6562ac5a4f7885c1a995999336cd3aa

Share on LinkedIn
Print
ZIP Archive
MD5: b6562ac5a4f7885c1a995999336cd3aa
Size: 105.25 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b6562ac5a4f7885c1a995999336cd3aa
Sha1 61670f724cd74cfe29384502050b50dc6da369e0
Sha256 ea6a0df56f91552d3030b0a3db6358fbe83e92895e7bf58188f34efa5e1093a5
Sha384 9dc154a5d3e20c34b36de549f4532cb2a573777c501679fe3dd4235b98dea122158eb3651d44a730b605e21a8c6e8788
Sha512 762e3753b0c4890526e101bad422615f40a48695db16f50b62b2199f417e0a99c35a0e98f0310a56fa78e67f4cc88656c2058f3e96df6507f7a7a42afe08a937
SSDeep 1536:TC0I5lsjvpexIKqNVQFc2DT6E//F39CLA9ylvat1snH9gPSsfB3oSIcilBNy:u0Sl2v66V+T6utCL9CtOH9+SaVITfNy
TLSH 33A312E563FEAC7DD673308D8563152C3900A0E704AE2BADB53882C955B9B47D82C29F
.Net Resources
Malicious
Start-Library.ps1
Malicious
[PowerShell Command]
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 1img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe>scr:ps1~T1059.001~T1105
Shape arc:zip>pe:exe>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙