Malicious
Malicious

1b149ec9f6c12af5d9d2f91edf57dc43

PowerShell
MD5: 1b149ec9f6c12af5d9d2f91edf57dc43
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1b149ec9f6c12af5d9d2f91edf57dc43
Sha1 d361873534fb759775e62c213cc306fefcdecb39
Sha256 48ff473b3f8ec097950aab70dd93d51c274591efd786005de73a4c24ac6545be
Sha384 9a6b5de6dcdd77372006d7ffefb7dfca6f1788bcaca2b99a0da0f50d96c98e5d3dd83620d62dab69f76da5c46dfe989d
Sha512 c6c0c37be0f68be006580503cc0637d2b7fd9f39b27f8630d7bdcd23cb438af5000ac2a7b38977ba60f19ae3a15d3982b3a85ecc32a75d469e38a266facaae30
SSDeep 12288:+8pHmq5dNUM0jffqUlwL7FJU8dabStiGwOdU8D7IgxfaVqwL2+7rpP/0uziUM3ii:P
TLSH FD5521523551FD7D029693B17E1646F0A86ACA40CFDF8556F24DCE88A14EC863AFA3C3
1b149ec9f6c12af5d9d2f91edf57dc43
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
1b149ec9f6c12af5d9d2f91edf57dc43
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
1b149ec9f6c12af5d9d2f91edf57dc43 › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙