Malicious
4160223ab42e6c414c2387ff33173a30
PowerShell
MD5: 4160223ab42e6c414c2387ff33173a30
Size: 68.27 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4160223ab42e6c414c2387ff33173a30 |
| Sha1 | 95cef82171b638074cf4bd0e8a3f875e55db9841 |
| Sha256 | 8f8239a8b0e30eca06fce80fbf744a596d3a74bbe53f3a14d26e090bd4541397 |
| Sha384 | f937ece5e49486d95537fff47a90ff0924f4c96708605ebf82becf1144ce56cc6713cb8bc0c19d78b75ade5a808cf1ac |
| Sha512 | 1ac233535c8e4ae2c09739760ece6e73968c74211660dd209722d27481151a3b7e6a83a550d2dd1c505fa2efa88a2dd3eed5b3456c684b54ccf700703fab72ff |
| SSDeep | 1536:4X/eqvLNNXT+H5HOYlR6jzjFH/JCHsd1XQrbGvz1f:4X26LNxG4YlR6jzNYHk1gryLt |
| TLSH | A56354533AA442E9328DCEB20E40546DDEE6F033D29EA55C76CD68C8B7B37A452E4C35 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell
UNKNWOWNmalicious
ise | huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
(?i)
huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell
UNKNWOWNmalicious
ise | huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30 › [Deobfuscated String]
Deobfuscated PowerShell
UNKNWOWNmalicious
(?i)
huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30 › [Deobfuscated String]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.