Malicious
Malicious

47f804569cc619e52a475cbc82f1a51b

Share on LinkedIn
Print
PowerShell
MD5: 47f804569cc619e52a475cbc82f1a51b
Size: 3.39 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 47f804569cc619e52a475cbc82f1a51b
Sha1 d5cb15f70ac11986d7eec2c2f9c47030f813a1f7
Sha256 3e6b4867e1c5ea27e72b0347342b6bb80c01c06394bb9373322ca2dadf5a7b81
Sha384 d03642003af7ade1ce8b94f478aef5bfe8f2434be4ea41e7c825212c0a06223360a86be5b995e02ae9847cf4b0ff7851
Sha512 4c1000ae7b7f4531d970b962e64a0645beccf05303c7213a6ad7ef2f74952ec7c95dc125a13838474b117fdfe1b5a338df9f628199c6dbfbaa2edc417d48e23a
SSDeep 96:aweDMd0poAiYDvMqTtPg3vD1Zdv2+fcKvWa:awF0lDvMqTtPg3vD1Zdv2yAa
TLSH D561B59BB23464C686C25642E5EA4901EB0DD9FE614A07E182FF5350EB31DBA87D8382
47f804569cc619e52a475cbc82f1a51b
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 htthuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhu
URL in PowerShell #3 httphuhuhuhu
URL in PowerShell #4 http:huhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhu
URL in PowerShell #6 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 htthuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 httpshuhuhuhuhuhuhu
URL in PowerShell #8 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #9 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
htthuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
httphuhuhuhu
URL in PowerShell #4 URImalicious
http:huhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 URImalicious
htthuhuhuhu
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #9 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7 URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #8 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙