Malicious
Malicious

3043e7a7793a87cb1e4a70df3d54a674

PowerShell
MD5: 3043e7a7793a87cb1e4a70df3d54a674
Size: 1.43 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3043e7a7793a87cb1e4a70df3d54a674
Sha1 93dc2b831823f6a4b7cad478672e5511afda923a
Sha256 f6fe88b7c90cfbfca749498320d01a147d019b8d8473c80557507a215352e4d5
Sha384 55629f11e72ddafb3694eb2a0aac985f67df9f5a56178340d3d5541814cde802d3ddc44c51e10b79cb3cda662bc80a0b
Sha512 f761817a78e168f372e31df5c256eedc5723e486bac39ab8c25b53338650974a399637caf1cb40152a33ea1751fd37f72ed30292da7e552323a6c9bdb5cf5290
SSDeep 12288:rjsUhG5fBOR3RFIpGvSYgyCJS2wdUuQDP7IoKwMqx8LlzsuHNSW3itbe4pXJFeoq:HtV
TLSH F66500523A51FD7D029793B16E1646F0A46ACA40CEDF8556F24DCE88B14DC863AFA3C3
3043e7a7793a87cb1e4a70df3d54a674
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
3043e7a7793a87cb1e4a70df3d54a674
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3043e7a7793a87cb1e4a70df3d54a674 › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3043e7a7793a87cb1e4a70df3d54a674
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3043e7a7793a87cb1e4a70df3d54a674
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙