Malicious
0534b4e2d76045807ae1a970c31eeb72
PowerShell
MD5: 0534b4e2d76045807ae1a970c31eeb72
Size: 672 B
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 0534b4e2d76045807ae1a970c31eeb72 |
| Sha1 | 70ca5df16edfb26dc7908cb4c059a9b96dce8aec |
| Sha256 | 5cdfbead37505dccb8ba9704be19905e21e1786e01f70a738fe92e23720792be |
| Sha384 | 2fe641a65896ff01652e235f3236fed872fb728113ccef7c69fa09358a0d79a6792ee749ec539907fc904b1ec140b9bc |
| Sha512 | 975d9eb5f2f526488fe502d6ae3ee7c8e1203872f0d9770777a275ff455c5eff2f8ff83ab4134ebb76d5db53b9b33b1f57e0805f3e13b305a514799cdfe42f3e |
| SSDeep | 12:eR9ebZzjrA7uL3sOM7fXF3OubEsEL3uMeVyOExiAUzciUXSbLGDYn:Y98jr8uzvKP8p0VyOEekX+iE |
| TLSH | 2A01FEA71BA4CC1840C65460530BF0A1E15BAE8F305D9C46B9D9ED86E678F45AA48259 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell
UNKNWOWNmalicious
$w = Nhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell
UNKNWOWNmalicious
$w = Nhuhuhuhuhuhuhuhuhuhuhu
0534b4e2d76045807ae1a970c31eeb72
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
0534b4e2d76045807ae1a970c31eeb72
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.