Malicious
Malicious

3b1d9ae65dd6dd1229ebe9928676454e

PowerShell
MD5: 3b1d9ae65dd6dd1229ebe9928676454e
Size: 5.45 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3b1d9ae65dd6dd1229ebe9928676454e
Sha1 7aa1f917dd58abf1b8e66a3842c53d0384c29066
Sha256 64258a04e00ca400cb089e6f2d2cd562b1f33755ba7b58a1ed2b3fd282faedff
Sha384 a812b959304c5afe417283266f83cc2430446ff6a02d493373de0c2b7e374ac0156346ea5b50ffb9c711f3375d789be2
Sha512 d15e91d7be6b42090eb772b536ec9edbb910c69ce5e348b735566f45a7e5a8d25f380bd270bf046134d93c52e585cb094f6ffcdc0be1c53cba13609b1975dcd8
SSDeep 96:5PSuQf8lt6bBoPTXnY19Kizr7qzi9/kIjVgH3kezx9jokHXX/NFjuM:5PSus8l4bB+TIyAXqzlLxxrXXlFjz
TLSH 24B1E757F7AD87AC505E96E1AC82760EFB42C13E917618A8D2E8E18455C3ED53FAC034
3b1d9ae65dd6dd1229ebe9928676454e
Malicious
[Deobfuscated String]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001
Shape scr:ps1
malicious 1 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
3b1d9ae65dd6dd1229ebe9928676454e
Malicious
[Deobfuscated String]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhu
3b1d9ae65dd6dd1229ebe9928676454e › [Deobfuscated String]
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
3b1d9ae65dd6dd1229ebe9928676454e › [Deobfuscated String]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙