Malicious
Malicious

15a8f93f2f5c64e0ca08939f6a826b94

PowerShell
MD5: 15a8f93f2f5c64e0ca08939f6a826b94
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 15a8f93f2f5c64e0ca08939f6a826b94
Sha1 29f4c14dfab363f966c01fb5e6f4467eb4b2b0d0
Sha256 99a5df049e5d8368a67ecbaf54ec4001dca48fd4e4ce2bcb37a10cd698f5a03d
Sha384 ce2b99b7e966325201f4cbcc0bc8f5a33d15d42812802fc7ae20927d69cf1a547b86030c85fa586c05b1289f119018fd
Sha512 3e6efcd71a78e05056f2b5bd1970dd9989de1c6908bab109158a32d2c01ffb539e8ff2f574815dd14146ffaca1f73e70d96d8d5a8116ad4311cdb669125260f4
SSDeep 12288:2pv1enrDHADflIt0tBXTxre9rkXAL7hgmJwqCUxuizNwqgG0cxfOLhsdcR6W0e9Q:om
TLSH 926510523651FD7D029793B56E1646F0A86ACA40CEDF8556F24DCE88B14EC823AF93C3
15a8f93f2f5c64e0ca08939f6a826b94
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
15a8f93f2f5c64e0ca08939f6a826b94
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
15a8f93f2f5c64e0ca08939f6a826b94
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙