Malicious
15a8f93f2f5c64e0ca08939f6a826b94
PowerShell
MD5: 15a8f93f2f5c64e0ca08939f6a826b94
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 15a8f93f2f5c64e0ca08939f6a826b94 |
| Sha1 | 29f4c14dfab363f966c01fb5e6f4467eb4b2b0d0 |
| Sha256 | 99a5df049e5d8368a67ecbaf54ec4001dca48fd4e4ce2bcb37a10cd698f5a03d |
| Sha384 | ce2b99b7e966325201f4cbcc0bc8f5a33d15d42812802fc7ae20927d69cf1a547b86030c85fa586c05b1289f119018fd |
| Sha512 | 3e6efcd71a78e05056f2b5bd1970dd9989de1c6908bab109158a32d2c01ffb539e8ff2f574815dd14146ffaca1f73e70d96d8d5a8116ad4311cdb669125260f4 |
| SSDeep | 12288:2pv1enrDHADflIt0tBXTxre9rkXAL7hgmJwqCUxuizNwqgG0cxfOLhsdcR6W0e9Q:om |
| TLSH | 926510523651FD7D029793B56E1646F0A86ACA40CEDF8556F24DCE88B14EC823AF93C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.