Malicious
Malicious

3dae16b34762512f7fa6c027857f371e

PowerShell
MD5: 3dae16b34762512f7fa6c027857f371e
Size: 1.66 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3dae16b34762512f7fa6c027857f371e
Sha1 bc89f1aa50ae33f237f20dbc1b72ce86824712a3
Sha256 435475ac115a91544e9c4fc17551ed14cb241cf1b8a0c70f1f6e20043406925e
Sha384 00d61163c662b118a8e05a03693d7487499138c6dce43a9a94132ffc1e73fe18d73ebb2a5101148056e02f5a3d8c1b73
Sha512 ec9fcfcd2c5a1fefe38484e834c2482f81d606fa35c7a15afe78af36ed3cece6fd1967db2daf66925b782cf44b15dc33b3b068550d89001fc8e9cfa87b514d73
SSDeep 12288:kUwWhuxyGyQOiPm1y9ptV4jxeRRHWd+oKSbfngBLkeYYI/VD7p3ArRqch8IiHCBr:a
TLSH 047500523651FD7D029693B56E1646F0A86ACA80CEDF8556F24DCE8CB14DC823AF93C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e › [PowerShell Command]
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e › [PowerShell Command]
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
3dae16b34762512f7fa6c027857f371e › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙