Suspect
41b3f3fc28d638d136c030290d30c29b
PowerShell
MD5: 41b3f3fc28d638d136c030290d30c29b
Size: 11.99 KB
application/x-powershell
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 41b3f3fc28d638d136c030290d30c29b |
| Sha1 | cbb15747a58326f57a693d3b6d9dccbd619c70fb |
| Sha256 | 5898cab97f4e82f4b3fc1ded1f26c7c3451ab137dcffffeaa68e6360558ad607 |
| Sha384 | 1243b193cd8e749259733de826cc6452ebdeae161a9b400b3e5d929d5e81cc36a1cb635df902f36534f24aefb518f740 |
| Sha512 | 4a7e87dee2170986518cc239e5e46dbec836e325a5888664435f95de57508789746edd3b5e42f632187810cb9d924eceb1eb1009c664cd215a0f252a8f7c3f5f |
| SSDeep | 192:XNu4AkGDkQ4pj2qnukql7mZiIKFIx/3P+5KIQcCDP3CLiVj5I6gCYh5KIQcee:XMXKQlx6+5KIQzLMc8h5KIQE |
| TLSH | 3532B85ABF032058C6F3DBBFBCD35209EA524037898B3818B5EDD1952FB196847AD14C |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
technique1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #5 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #5 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #6 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #4
URImalicious
httpshuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #5
URImalicious
httpshuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
URL in PowerShell #6
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
41b3f3fc28d638d136c030290d30c29b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.