Malicious
Malicious

3dae16b34762512f7fa6c027857f371e

Share on LinkedIn
Print
PowerShell
MD5: 3dae16b34762512f7fa6c027857f371e
Size: 1.66 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3dae16b34762512f7fa6c027857f371e
Sha1 bc89f1aa50ae33f237f20dbc1b72ce86824712a3
Sha256 435475ac115a91544e9c4fc17551ed14cb241cf1b8a0c70f1f6e20043406925e
Sha384 00d61163c662b118a8e05a03693d7487499138c6dce43a9a94132ffc1e73fe18d73ebb2a5101148056e02f5a3d8c1b73
Sha512 ec9fcfcd2c5a1fefe38484e834c2482f81d606fa35c7a15afe78af36ed3cece6fd1967db2daf66925b782cf44b15dc33b3b068550d89001fc8e9cfa87b514d73
SSDeep 12288:kUwWhuxyGyQOiPm1y9ptV4jxeRRHWd+oKSbfngBLkeYYI/VD7p3ArRqch8IiHCBr:a
TLSH 047500523651FD7D029693B56E1646F0A86ACA80CEDF8556F24DCE8CB14DC823AF93C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙