Malicious
c5c2ae23fa34d045d6a887f9b3977eab
LNK File
MD5: c5c2ae23fa34d045d6a887f9b3977eab
Size: 2.05 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | c5c2ae23fa34d045d6a887f9b3977eab |
| Sha1 | 378193e34a149670163752e629cea6855cfe78b8 |
| Sha256 | b902772635036ffdbc8f34877d923306ad1a66247fce31ca63fc0380c929542c |
| Sha384 | d0807c5eb7b4f181f3a1d0aff036d7ec1a48518e36072a2d1275d1fe9806cfc253000274b7646058a139b147b10fc8f0 |
| Sha512 | 5a99bfda6a1c307944dda02115609f45259108c821fa994496e978521c7b72b0c37977a1f86463f8fbca03404b04aef132d127057765f157d8e480724289d62b |
| SSDeep | 24:8SPBAW9lKpqVD8FpHKnWWXtlAUW5+/CWPWe/CDCOPnSPoY4I0W4vQpK6+/CUPHqg:8SPDlxVDsWXtONTnsonItB6HitSq4WY |
| TLSH | 22418C2427F90324E3BB8B7BACB6F31256367C50E9935BCE129056885828525E476F2F |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape
lnk>lnk:cmd>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
LNK: Command Execution
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab
Deobfuscated PowerShell
UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab › LNK CommandLine › [PowerShell Command]
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
c5c2ae23fa34d045d6a887f9b3977eab › LNK CommandLine › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.