Malicious
065d82811aaa439c952ad689e3bd16d6
PowerShell
MD5: 065d82811aaa439c952ad689e3bd16d6
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 065d82811aaa439c952ad689e3bd16d6 |
| Sha1 | 59cca454070fe3fb32de3fc22d8314690fde18cf |
| Sha256 | b92ed2926ff505f31b993ae311b1902dcf5a72f6431177d79fcc51368821859a |
| Sha384 | 32549bb4b88e716aee55f334e60189b1ffae2c8428fe736184dde725e15f9699600a99fe4a9d088a13345af10d5af4e9 |
| Sha512 | db4ac9aa308d4e940c94d876a8354277df291995c8914e2df478be9e50ac204fc05b67ae82db8f8d92a45e0123c9a476d17c6fa3a7c1a48ac32adf1b00e22b5d |
| SSDeep | 12288:c/9N0cR0bFYIgj8mauBROt/ao6agkqvu1lzZ63WRtREJGj2cg6GtLkgNIoFMzpdw:Y |
| TLSH | 5E5522523651FD7D029693B16E1646F0A46ACA80CFDF8556F24DCE8CA14DC823AFA3C7 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
065d82811aaa439c952ad689e3bd16d6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.