Malicious
ceeda3eea9f4e2ca4e9d05e9d599c727
PowerShell
MD5: ceeda3eea9f4e2ca4e9d05e9d599c727
Size: 3.56 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | ceeda3eea9f4e2ca4e9d05e9d599c727 |
| Sha1 | 6121394cba50fe0eba91f96cfc3cb7db7884d476 |
| Sha256 | 4bd18a93b32bec47e0f12605891d01686e59208c79ec7d226da153e50da650fb |
| Sha384 | 98b933311a529680d842ad166d046c894cac77da31e1f73112e3eb86571b132585fe778a08bcd4db5e565023bb14720e |
| Sha512 | 12187d65d8aee65588cc06894fb513dea441b5ce1ad9ae67c305c40e4ea4f1770db06ed4c3262ea439d4e7901611ec488cd5f3bfee5c094ad39c567d4ae1cb83 |
| SSDeep | 96:aw+oWnyinf9JZqjLVVol0/H6JhT/2/r1V:aw+oWnl1JZAml0/s/2// |
| TLSH | 3C7101037707E1758CB18BB6C99FA809D5E02D976C0F08457DCD89D26F3539AB5F90A2 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:ps1>scr:vbs>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727
Deobfuscated PowerShell
UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727 › ceeda3eea9f4e2ca4e9d05e9d599c727.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.