Malicious
Malicious

2d6cd66eef703ac33fc34b4de8ec596b

PowerShell
MD5: 2d6cd66eef703ac33fc34b4de8ec596b
Size: 6.73 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2d6cd66eef703ac33fc34b4de8ec596b
Sha1 a907fe413d5a74fa7e88e20f0682a0d4d0f63716
Sha256 12c01bc666634a74c6d75ef80ee39a2f859e6e50896658a01817518b5a78712f
Sha384 4ddef5edf20055d07a6bd50bbcdd748deb98dec6677dd4e12ad5ef901b11868431615af960e8324abd68d47fb407ef68
Sha512 9cd0dfa96f695c716731d13bbfda1059b23a85af55d0f0e1fe96bcec38ade53e5731f063babd80b94383b8eacd00bb176b00b195dcc5a6feb392a2029cc49181
SSDeep 96:J00CE0Mmb51faCB0p8UenvVHuc22aI1v7eTje/weY4Kmb5W:Kqm51fzy8UevVOjnIZ7eHe/wezKm5W
TLSH DDD132096A5142A1C631AB758DE32B4BF61F047B5117024075ACD285FFB0AAED7FDE8C
2d6cd66eef703ac33fc34b4de8ec596b
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001
Shape scr:ps1
malicious 1 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
-noprohuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
2d6cd66eef703ac33fc34b4de8ec596b
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
-noprohuhuhuhuhuhuhuhuhuhuhu
2d6cd66eef703ac33fc34b4de8ec596b › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
2d6cd66eef703ac33fc34b4de8ec596b › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙