Malicious
4eb56d042c5450166834e70e49a87a7c
PowerShell
MD5: 4eb56d042c5450166834e70e49a87a7c
Size: 696.13 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4eb56d042c5450166834e70e49a87a7c |
| Sha1 | 92bc9b7a4f6ceea540d8ab8cb5017d7b3619a279 |
| Sha256 | f249acb339b65e234a03c1c0bc7e3a4322ace2552fc5beea87cde829ddc73603 |
| Sha384 | 812850b2c54a4ef5357aad0a377f072b31147cd4871ebf858f726cce12711d615da8cf0cc1d66bbfd87d74ad01701f98 |
| Sha512 | 75f14569d99a03388438486498ff607ab907387aa0a4be7b2ef362b97104b5adfb38d8f8724367fd9035a4dd3c9f9bdcb44d9dbe31763172e4061708c4225619 |
| SSDeep | 12288:1OxsaWragRQPC8REtHP/Vp+TFX1SQfveFBpNqTHbLUFg0sPr9n7F/rDBR+:1OxsHRSEJOT9dfveba7eWrRFD1c |
| TLSH | 60E42320C7CA2F865B08DE3D609ACE49F9756842D47D54FD70EDB88EE3697420A4F42E |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | htthuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
htthuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | htthuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
htthuhuhuhu
4eb56d042c5450166834e70e49a87a7c
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
4eb56d042c5450166834e70e49a87a7c › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.