Malicious
Malicious

4160223ab42e6c414c2387ff33173a30

PowerShell
MD5: 4160223ab42e6c414c2387ff33173a30
Size: 68.27 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4160223ab42e6c414c2387ff33173a30
Sha1 95cef82171b638074cf4bd0e8a3f875e55db9841
Sha256 8f8239a8b0e30eca06fce80fbf744a596d3a74bbe53f3a14d26e090bd4541397
Sha384 f937ece5e49486d95537fff47a90ff0924f4c96708605ebf82becf1144ce56cc6713cb8bc0c19d78b75ade5a808cf1ac
Sha512 1ac233535c8e4ae2c09739760ece6e73968c74211660dd209722d27481151a3b7e6a83a550d2dd1c505fa2efa88a2dd3eed5b3456c684b54ccf700703fab72ff
SSDeep 1536:4X/eqvLNNXT+H5HOYlR6jzjFH/JCHsd1XQrbGvz1f:4X26LNxG4YlR6jzNYHk1gryLt
TLSH A56354533AA442E9328DCEB20E40546DDEE6F033D29EA55C76CD68C8B7B37A452E4C35
[Deobfuscated String]
Malicious
[Base64-Block]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Deobfuscated String]
Malicious
[Base64-Block]
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
ise | huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30 › [Deobfuscated String]
Deobfuscated PowerShell UNKNWOWNmalicious
(?i) huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30 › [Deobfuscated String]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
4160223ab42e6c414c2387ff33173a30
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙