Malicious
Malicious

06e8fc36f9ab2d33fe3aeb7dd0b5311c

PowerShell
MD5: 06e8fc36f9ab2d33fe3aeb7dd0b5311c
Size: 3.36 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 06e8fc36f9ab2d33fe3aeb7dd0b5311c
Sha1 695af4aee921a1d87411433f8bb92838f7af75fa
Sha256 4a8ce1750c2bf9cc5428b74e29cb754c41114030f98abb73a4f731fad6c2abb9
Sha384 afa475aa5dade52f63810337ec1135cf66d22ad681f4c54219b843bbd7eb989b102dc94507524850cb70e6a99953b61b
Sha512 05dd01303dbd681bfb62ddbd64495e443756474fa9846046fab9a0f62210254ffdfb8dd8a2e398627324659244dadba484d988c268d75d42f384450b5e96e8e4
SSDeep 48:EY1buq//1+++hMVy39MVKsA4J6C8H8v0vUxN03e3SQ6OOK+2mpII7dMtyCy9ifyI:IsGhMVPA4oCC/vENFCnKOpII7ejygf/
TLSH 4F61FA9BB63024D281C19502D9E60945EA9FD0DC16860BD0C2BF47B05F32F7D97AC3C5
06e8fc36f9ab2d33fe3aeb7dd0b5311c
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 httphuhuhuhu
URL in PowerShell #7 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 httpshuhuhuhuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
httphuhuhuhu
URL in PowerShell #7 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
06e8fc36f9ab2d33fe3aeb7dd0b5311c
Malicious
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 httphuhuhuhu
URL in PowerShell #7 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 httpshuhuhuhuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #4 URImalicious
http:/huhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #6 URImalicious
httphuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #7 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #9 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #4 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #7 URImalicious
httpshuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
06e8fc36f9ab2d33fe3aeb7dd0b5311c › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙