Malicious
Malicious

33f727d5b74de35491057cc4c73e74c0

PowerShell
MD5: 33f727d5b74de35491057cc4c73e74c0
Size: 12.52 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 33f727d5b74de35491057cc4c73e74c0
Sha1 d479762d52b5f897273a9d343c0ed6803359b9ce
Sha256 a256a971b794804b6933f8eff4a3e34cbcc69775c5728b50efe093011600ea8c
Sha384 7e48f7910e3f269df269e2ac4559aa3c936a4d1c2eb78fd357eec2e3faf5cd981eb7aac5e5ca60a7a6b92d6672a97e1c
Sha512 3a3b97cf7c2e970df475a22fe8da3df4b7dd6e91a3a50c7ffdc76f8f6bb698b6413d4f6e8ec8da8cac632e69bee8de47b5a740f2808a02710ea9ec22dd6b4dc5
SSDeep 192:SyYseJ5kF3oFis7sR4puJFcwdY5OKR+suCfNQHd1pEVgONUNKx8U/Q//nyiWytIF:sss5kFa7+4pTOKOGZ/9
TLSH 7E428519225A95418BA775AFC9DF38028E9A20377049A81F7ADFE2D4DF4C17CD02A7CC
33f727d5b74de35491057cc4c73e74c0
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
33f727d5b74de35491057cc4c73e74c0
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
33f727d5b74de35491057cc4c73e74c0
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
33f727d5b74de35491057cc4c73e74c0
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙