Malicious
Malicious

23cab357fe9387227d137ca0e0afc518

PowerShell
MD5: 23cab357fe9387227d137ca0e0afc518
Size: 96.18 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 23cab357fe9387227d137ca0e0afc518
Sha1 ce74481a0ae28caf31c16ea23125ab03d5cb09e2
Sha256 49cc7fd35a16329bde9aa2446e0e014c08f246730402a1ee14981a641d634848
Sha384 861442ef5c9e44a2bb15826056208c5cb2d43d73cd328bc9de7d8cebcd39fb2d2802ad1ea7bbe3b75e0278fa6f3c0e60
Sha512 2f4fe8d810e81bb63e2f61bce291d5aaca86142930c6425e52e7a2b8b464c3dd294059bda6a888b4bf37bbf018451d76c47ff09a02c2ab39457dbc3cca493b25
SSDeep 1536:be1FJGsdpjk0oNuPtgtQCTpnF9Q90adz4zcpNpfO+GL1jfrwNdH9/qSw7ieYi:bkF8spjPyuP+JpF9Q9Pz4zWOL1jfUnBu
TLSH CE9323053B8C95E010CDDDBE0FC06CA956AEE072D3DADC9C66CF5A84AB43AFA459C474
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
23cab357fe9387227d137ca0e0afc518
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
23cab357fe9387227d137ca0e0afc518 › [Deobfuscated String]
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhu
23cab357fe9387227d137ca0e0afc518 › [Deobfuscated String]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙