Malicious
ef04575a2fae8de5199cac82a3621e30
PE Executable
MD5: ef04575a2fae8de5199cac82a3621e30
Size: 5.47 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ef04575a2fae8de5199cac82a3621e30 |
| Sha1 | 13e747467edc75c07cdcc78e7094e7feced573f9 |
| Sha256 | 99bd3aa2659a7c95c09be896b06e809c948d089dceb2acbbe53bf576b2370856 |
| Sha384 | d91fbb6207bfa4a73415e362c2ee0f1209ac331320024f286a7dba6f2c3d97a85af54887f036807cfd670e0048ef1ce4 |
| Sha512 | 038dc6c3d25370382dab3aeefab48c49ba0ddf1605e76cd53eb3ef6bfcff102c77d9c2de1b3d52ac2f55e8f1e9a601674d724f637f0b7dcd58383eff83614afe |
| SSDeep | 98304:rKAu43Gt8dy3X8zxRa49EqrHB5EMyQ0VGcK/IYDO6Kgzepk3U6uLGnt:rrWt+R9hrTEMj0n36Kzk3U7LGnt |
| TLSH | C346230AF7E409F9E173D0B5CE914502E772BC8A1762D69F03A1A9B51F272A0DE3D712 |
PeID
Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 11
STICH kept: 3secondary ignored: 8
bin
7img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
pe:exe>arc:rar>arc:rar>scr:ps1~T1027~T1059.001~T1105
Shape
pe:exe>arc:rar>arc:rar>scr:ps1
malicious
4 nodes
Path
pe:exe>arc:rar>arc:rar>scr:ps1~T1059.001~T1105
Shape
pe:exe>arc:rar>arc:rar>scr:ps1
technique4 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhu |
| URL in PowerShell #8 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhu |
| URL in PowerShell #10 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #11 | https:huhuhuhuhuhuhu |
| URL in PowerShell #12 | https:huhuhuhuhuhuhu |
| URL in PowerShell #13 | https:huhuhuhuhuhuhu |
| URL in PowerShell #14 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #8 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_0016fdab.bin (4992187 bytes) |
| Info | PDB Path: D:\Projects\WinRAR\SFX\build\sfxrar64\Release\sfxrar.pdb |
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #8
URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #10
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #12
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #13
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #14
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #8
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
write-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhu |
| URL in PowerShell #8 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhu |
| URL in PowerShell #10 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #11 | https:huhuhuhuhuhuhu |
| URL in PowerShell #12 | https:huhuhuhuhuhuhu |
| URL in PowerShell #13 | https:huhuhuhuhuhuhu |
| URL in PowerShell #14 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #8 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #7
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #8
URImalicious
httpshuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #10
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #11
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #12
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #13
URImalicious
https:huhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #14
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › utils › test zapret.ps1
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #4
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #5
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #7
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #8
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
write-huhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
ef04575a2fae8de5199cac82a3621e30 › Overlay_0016fdab.bin › zapret-discord-youtube-main.rar › zapret-discord-youtube-main › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.