Malicious
Malicious

4eb56d042c5450166834e70e49a87a7c

PowerShell
MD5: 4eb56d042c5450166834e70e49a87a7c
Size: 696.13 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4eb56d042c5450166834e70e49a87a7c
Sha1 92bc9b7a4f6ceea540d8ab8cb5017d7b3619a279
Sha256 f249acb339b65e234a03c1c0bc7e3a4322ace2552fc5beea87cde829ddc73603
Sha384 812850b2c54a4ef5357aad0a377f072b31147cd4871ebf858f726cce12711d615da8cf0cc1d66bbfd87d74ad01701f98
Sha512 75f14569d99a03388438486498ff607ab907387aa0a4be7b2ef362b97104b5adfb38d8f8724367fd9035a4dd3c9f9bdcb44d9dbe31763172e4061708c4225619
SSDeep 12288:1OxsaWragRQPC8REtHP/Vp+TFX1SQfveFBpNqTHbLUFg0sPr9n7F/rDBR+:1OxsHRSEJOT9dfveba7eWrRFD1c
TLSH 60E42320C7CA2F865B08DE3D609ACE49F9756842D47D54FD70EDB88EE3697420A4F42E
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1027~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 htthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
htthuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 htthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
htthuhuhuhu
4eb56d042c5450166834e70e49a87a7c
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
4eb56d042c5450166834e70e49a87a7c › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙