Malicious
Malicious

ceeda3eea9f4e2ca4e9d05e9d599c727

PowerShell
MD5: ceeda3eea9f4e2ca4e9d05e9d599c727
Size: 3.56 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ceeda3eea9f4e2ca4e9d05e9d599c727
Sha1 6121394cba50fe0eba91f96cfc3cb7db7884d476
Sha256 4bd18a93b32bec47e0f12605891d01686e59208c79ec7d226da153e50da650fb
Sha384 98b933311a529680d842ad166d046c894cac77da31e1f73112e3eb86571b132585fe778a08bcd4db5e565023bb14720e
Sha512 12187d65d8aee65588cc06894fb513dea441b5ce1ad9ae67c305c40e4ea4f1770db06ed4c3262ea439d4e7901611ec488cd5f3bfee5c094ad39c567d4ae1cb83
SSDeep 96:aw+oWnyinf9JZqjLVVol0/H6JhT/2/r1V:aw+oWnl1JZAml0/s/2//
TLSH 3C7101037707E1758CB18BB6C99FA809D5E02D976C0F08457DCD89D26F3539AB5F90A2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape scr:ps1>scr:vbs>scr:ps1
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727
Deobfuscated PowerShell UNKNWOWNmalicious
" & g_huhuhuhuhuhuhuhuhuhuhu
ceeda3eea9f4e2ca4e9d05e9d599c727 › ceeda3eea9f4e2ca4e9d05e9d599c727.deobfuscated.vbs › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙