Malicious
366ff58afe7e17ce899c4ea8fb8b23a7
PowerShell
MD5: 366ff58afe7e17ce899c4ea8fb8b23a7
Size: 1.4 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 366ff58afe7e17ce899c4ea8fb8b23a7 |
| Sha1 | 2b78b3c429f50846d946181c5744d410169f6171 |
| Sha256 | c33e34c82dbdfa28c784be6bfb376605c01b426274d2d68106fb9d1413a7fabc |
| Sha384 | 87b8be259b27e07a14f8188132d9b131000108c12f7e2d2313b661f23849b0fce3c1ef4fee18b91e0b8fd5b76c3a21c6 |
| Sha512 | 7a73b34e5e260e78e58260645b08f8fff99090b0be955d99502609c3d4c2e5169dc0f61a560c7e1d56e92ec31d288074eeccea31dbabd0cb06e6041b1a640029 |
| SSDeep | 12288:H+R5z5P6V6lEuZC0mzZSORAVtK3PFzF3MdXovj+vWNa1vqseFb7ZWU5y9NnYlbEA:H |
| TLSH | 7C5500523651FD7D029693B57E1646F0A46ACA40CFDB8556F24DCE88B14EC823AFA3C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7 › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.