Malicious
Malicious

3c79378d291fd7b003fd32588766dbf9

PowerShell
MD5: 3c79378d291fd7b003fd32588766dbf9
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3c79378d291fd7b003fd32588766dbf9
Sha1 3f3dadeca141a5eca7ca5d3b3a54b9ff150134aa
Sha256 4b5215ae343c6dff3fabbd68214f42e5d59e4bdaa4d0ee3cfc45d6f9af07efec
Sha384 b6bff4bf9fba2ae474285840d2fa2e47124363b2e180a963c1939dd70a3a56192dc92b0f687dc0cf4cb64ac3ee920844
Sha512 d961c4f7d9f4aa11fde344b80479020ca43eace590c864da6b7b6d95f9dc73f4b3b77b00809cfc19ca7dde7be83bc5914f6c6fbd092929d98e2cddbad6c00e7c
SSDeep 12288:Bp1/UTAQHaiXzOS8fkvGxXawtb3J9V7KXUYk9y4IAnsrgVyvanpV57UgCoaLXrrX:0
TLSH 186522523A51FD7D029693B16E1646F0A86ACA40CFDF4556F24DCE8CA14EC863AF93C3
3c79378d291fd7b003fd32588766dbf9
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
3c79378d291fd7b003fd32588766dbf9
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3c79378d291fd7b003fd32588766dbf9 › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3c79378d291fd7b003fd32588766dbf9
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3c79378d291fd7b003fd32588766dbf9
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙