Malicious
Malicious

1e242bae5a4dacfa7651e8724ee95085

PowerShell
MD5: 1e242bae5a4dacfa7651e8724ee95085
Size: 1.37 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1e242bae5a4dacfa7651e8724ee95085
Sha1 b53d78180c1b1a3ba9fdacfbc09d78b0fcce7142
Sha256 b3dcf492b51fab2d011f1e53a4d590238f625190aa8e8d30b4177438024e1f7a
Sha384 bbff35a75c103cc10a55ef100641d4ad42f87158cd3fdf3667c3a473e9d2177a4f7d5ccbdcd6ff852add8c6992d51762
Sha512 a589057f9f980a9e83775c566c33b4d125e8caff34633fc18a8860a577d8843c358ef91a6c2d4f4c924badeacd8c60f1b9a654ac789e502ea3f94878d9288d16
SSDeep 12288:NN+CrOWffhyN2JFX1rYt5FqGSV5VDd3nV9W7cE2RXckvhx16IxFxdSMEz8tytKw3:I
TLSH 9D5510523A51FD7D029693B17E1646F0A46ACA40CEDF8557F24DCE88A14EC863AF93C3
1e242bae5a4dacfa7651e8724ee95085
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
1e242bae5a4dacfa7651e8724ee95085
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
1e242bae5a4dacfa7651e8724ee95085
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
1e242bae5a4dacfa7651e8724ee95085
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
1e242bae5a4dacfa7651e8724ee95085
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙