Malicious
Malicious

065d82811aaa439c952ad689e3bd16d6

PowerShell
MD5: 065d82811aaa439c952ad689e3bd16d6
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 065d82811aaa439c952ad689e3bd16d6
Sha1 59cca454070fe3fb32de3fc22d8314690fde18cf
Sha256 b92ed2926ff505f31b993ae311b1902dcf5a72f6431177d79fcc51368821859a
Sha384 32549bb4b88e716aee55f334e60189b1ffae2c8428fe736184dde725e15f9699600a99fe4a9d088a13345af10d5af4e9
Sha512 db4ac9aa308d4e940c94d876a8354277df291995c8914e2df478be9e50ac204fc05b67ae82db8f8d92a45e0123c9a476d17c6fa3a7c1a48ac32adf1b00e22b5d
SSDeep 12288:c/9N0cR0bFYIgj8mauBROt/ao6agkqvu1lzZ63WRtREJGj2cg6GtLkgNIoFMzpdw:Y
TLSH 5E5522523651FD7D029693B16E1646F0A46ACA80CFDF8556F24DCE8CA14DC823AFA3C7
065d82811aaa439c952ad689e3bd16d6
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
065d82811aaa439c952ad689e3bd16d6
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙