Malicious
PowerShell
MD5: 4203f0d49d69aee6d9ef6f7f640f9464
Size: 6.85 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 4203f0d49d69aee6d9ef6f7f640f9464 |
| Sha1 | 93779cd66ec905ff60c885e3d6f7af9f12294935 |
| Sha256 | 5187a79197eaed3de362a3ab5a332dadcebc64810beeba7c70846cce871786d3 |
| Sha384 | 088999131c3d58258e399f36bdcbd21a9720ce0c8a8b9cbedf7b1988286b975d940d9259cfc0fc5999225a6c931d7909 |
| Sha512 | b9864f077dc1a0b9b4f0a0db2efd9e2a95a575ca4d1b8dceba1b9622135a5a69562efbd0ad1869a7e937ad5cf1e2899b43b2ab6a18879a6641ed4d094929bba5 |
| SSDeep | 96:jCMb/MlX9aZUCGX+rnYlt00Emq8Qf7KgBjldG6qTvfjyvj:ei/MDayFXFQ2al86qrqj |
| TLSH | DFE1301EBC0B93344A76855A2C7DEC0DF7F116A7A1248864BD8C44469F345EEE8E4ACD |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059~T1059.001~T1059.005~T1105>scr:vbs~T1059.005>scr:ps1~T1027~T1059.001
Shape
scr:ps1>scr:vbs>scr:ps1
malicious
3 nodes
Command (COM trace) #1
UNKNWOWNmalicious
wschuhuhuhu
Command (COM trace) #2
UNKNWOWNmalicious
whoahuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential