Malicious
PowerShell
MD5: 47f804569cc619e52a475cbc82f1a51b
Size: 3.39 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 47f804569cc619e52a475cbc82f1a51b |
| Sha1 | d5cb15f70ac11986d7eec2c2f9c47030f813a1f7 |
| Sha256 | 3e6b4867e1c5ea27e72b0347342b6bb80c01c06394bb9373322ca2dadf5a7b81 |
| Sha384 | d03642003af7ade1ce8b94f478aef5bfe8f2434be4ea41e7c825212c0a06223360a86be5b995e02ae9847cf4b0ff7851 |
| Sha512 | 4c1000ae7b7f4531d970b962e64a0645beccf05303c7213a6ad7ef2f74952ec7c95dc125a13838474b117fdfe1b5a338df9f628199c6dbfbaa2edc417d48e23a |
| SSDeep | 96:aweDMd0poAiYDvMqTtPg3vD1Zdv2+fcKvWa:awF0lDvMqTtPg3vD1Zdv2yAa |
| TLSH | D561B59BB23464C686C25642E5EA4901EB0DD9FE614A07E182FF5350EB31DBA87D8382 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | htthuhuhuhu |
| URL in PowerShell #2 | http:/huhuhuhuhuhuhu |
| URL in PowerShell #3 | httphuhuhuhu |
| URL in PowerShell #4 | http:huhuhuhuhuhuhu |
| URL in PowerShell #5 | http:/huhuhuhuhuhuhu |
| URL in PowerShell #6 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | htthuhuhuhu |
| URL in PowerShell #8 | http:/huhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #10 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #11 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #4 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #5 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #6 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #7 | httpshuhuhuhuhuhuhu |
| URL in PowerShell #8 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #9 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #10 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #11 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
htthuhuhuhu
URL in PowerShell #2
URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
httphuhuhuhu
URL in PowerShell #4
URImalicious
http:huhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7
URImalicious
htthuhuhuhu
URL in PowerShell #8
URImalicious
http:/huhuhuhuhuhuhu
URL in PowerShell #9
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #10
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #11
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #7
URImalicious
httpshuhuhuhuhuhuhu
URL in PowerShell #8
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential