Malicious
Malicious

388636d04a2e5f85c93f67db34fd7722

PowerShell
MD5: 388636d04a2e5f85c93f67db34fd7722
Size: 3.31 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 388636d04a2e5f85c93f67db34fd7722
Sha1 18347b54073f7d63bd85553d29e3751918c61ea3
Sha256 b2bdb2a4e93fb7d4e2d6f87fc27e8016f64b31a53d373bf34c1ceeec02875041
Sha384 36d94e746969ee894020ad4644784f22af985ba96f38521ad5fb742fccf46a6a4b6ddcfee372e6eccf0b49060b5ba58e
Sha512 d7fa38ac092b1ecb642f9c15462479b8e3b73fae78fb1654ee0b3794947c7eac8eb929038af3e720251b4dddc92172e3f0643216f976123030880bbfad91e8de
SSDeep 96:U3im6NnztX94QjCZ548e36xih4AE+b1Hf:U3ibNztN4Q+Z548eqxihIuHf
TLSH C461A85AB7D0E2B18AB31919CCC5A795643B407221135610B2BD87547F9CD9FC7A33CA
388636d04a2e5f85c93f67db34fd7722
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
388636d04a2e5f85c93f67db34fd7722
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
388636d04a2e5f85c93f67db34fd7722
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
388636d04a2e5f85c93f67db34fd7722
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
388636d04a2e5f85c93f67db34fd7722 › [PowerShell Command] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙