Suspicious
Suspect

41b3f3fc28d638d136c030290d30c29b

PowerShell
MD5: 41b3f3fc28d638d136c030290d30c29b
Size: 11.99 KB
application/x-powershell

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41b3f3fc28d638d136c030290d30c29b
Sha1 cbb15747a58326f57a693d3b6d9dccbd619c70fb
Sha256 5898cab97f4e82f4b3fc1ded1f26c7c3451ab137dcffffeaa68e6360558ad607
Sha384 1243b193cd8e749259733de826cc6452ebdeae161a9b400b3e5d929d5e81cc36a1cb635df902f36534f24aefb518f740
Sha512 4a7e87dee2170986518cc239e5e46dbec836e325a5888664435f95de57508789746edd3b5e42f632187810cb9d924eceb1eb1009c664cd215a0f252a8f7c3f5f
SSDeep 192:XNu4AkGDkQ4pj2qnukql7mZiIKFIx/3P+5KIQcCDP3CLiVj5I6gCYh5KIQcee:XMXKQlx6+5KIQzLMc8h5KIQE
TLSH 3532B85ABF032058C6F3DBBFBCD35209EA524037898B3818B5EDD1952FB196847AD14C
41b3f3fc28d638d136c030290d30c29b
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
technique1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 httpshuhuhuhuhuhuhu
URL in PowerShell #5 httpshuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
41b3f3fc28d638d136c030290d30c29b
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 httpshuhuhuhuhuhuhu
URL in PowerShell #5 httpshuhuhuhuhuhuhu
URL in PowerShell #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #4 URImalicious
httpshuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #5 URImalicious
httpshuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #6 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙