Malicious
b8f815740b89f9ba3416a6e97d496202
LNK File
MD5: b8f815740b89f9ba3416a6e97d496202
Size: 1.41 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b8f815740b89f9ba3416a6e97d496202 |
| Sha1 | 8ee0308c3aa68051ad16e5db5617a2ef129f1540 |
| Sha256 | 24db809b9408a7c78be7947efe3bab4cd31ff104e6cf1d8a65c893b24857109c |
| Sha384 | 5e5213fb4235aec84b8454910e378a270279be2dc21a2a824d9aa8b95a211a8d727f6f63463e0176609214eb276ea306 |
| Sha512 | df53ef0c89aefc56b439af7bca436e06d4cb0f4211726822a586e86757b4da5aa34a8f3b766dda5b56c87192f625e7d5d93b4969eb2f6b679a6affa40072350d |
| SSDeep | 12:8X/OliNMlb+UE4M+s4XXMuvc/Gw6xWkWMlzmubdpYrn1Il+BdaY:8X/OliCEkRHLE/GHwr9qdd+Bd |
| TLSH | 5F21AC101BF51634F3B2493699726242AEBAB80EAF261A4E4146030C4873928D8F3F1B |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape
lnk>lnk:cmd>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
ARIB_UPD.LNK
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
ARIB_UPD.LNK › LNK CommandLine › [PowerShell Command]
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
ARIB_UPD.LNK › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.