Malicious
Malicious

cfec81df0304572e72e383c38722f50f

Share on LinkedIn
Print
Rar Archive
MD5: cfec81df0304572e72e383c38722f50f
Size: 1.92 MB
application/vnd.rar
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cfec81df0304572e72e383c38722f50f
Sha1 15cca745052649973bc2e7fe989d4216dc430dd5
Sha256 37471064f64d444ae89f427a4609ffe9df59908316708f10e0de291fb4809dcd
Sha384 2eb47bf3b8a4236e6743ca5099e19e5e9da72a28147d7c2d8f690fa269b04f1f438f41026dc96ceeb780590d09b974b9
Sha512 61d1ac16a1bfe2c3ac322688a0f94c8b980721d8a681b30adb3807a35aed8405bada22a07cd07fd408b5963fa8e745f5e706750165f5aa63aaaa8c8e3121cceb
SSDeep 49152:H5EtuezFil3R5FHhXG8kqKrpu6MyjZAjCtCmj:Z+ue4l3jVh/kqKr46Myj8CImj
TLSH 5E9533CA434166F1A26557DDB5A881CBFFE194A5B21BF0BF309C670461383E3C39A19B
cfec81df0304572e72e383c38722f50f
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Base64-Block]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:rar>scr:ps1~T1027~T1059.001
Shape arc:rar>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"+" "huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"+" "huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"+" "huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"+" "huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" " +huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
" "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙