Malicious
Malicious

366ff58afe7e17ce899c4ea8fb8b23a7

PowerShell
MD5: 366ff58afe7e17ce899c4ea8fb8b23a7
Size: 1.4 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 366ff58afe7e17ce899c4ea8fb8b23a7
Sha1 2b78b3c429f50846d946181c5744d410169f6171
Sha256 c33e34c82dbdfa28c784be6bfb376605c01b426274d2d68106fb9d1413a7fabc
Sha384 87b8be259b27e07a14f8188132d9b131000108c12f7e2d2313b661f23849b0fce3c1ef4fee18b91e0b8fd5b76c3a21c6
Sha512 7a73b34e5e260e78e58260645b08f8fff99090b0be955d99502609c3d4c2e5169dc0f61a560c7e1d56e92ec31d288074eeccea31dbabd0cb06e6041b1a640029
SSDeep 12288:H+R5z5P6V6lEuZC0mzZSORAVtK3PFzF3MdXovj+vWNa1vqseFb7ZWU5y9NnYlbEA:H
TLSH 7C5500523651FD7D029693B57E1646F0A46ACA40CFDB8556F24DCE88B14EC823AFA3C3
366ff58afe7e17ce899c4ea8fb8b23a7
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
366ff58afe7e17ce899c4ea8fb8b23a7
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7 › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
366ff58afe7e17ce899c4ea8fb8b23a7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙