Malicious
542a0c34d4bf2ca6630a14d899a596c2
PowerShell
MD5: 542a0c34d4bf2ca6630a14d899a596c2
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 542a0c34d4bf2ca6630a14d899a596c2 |
| Sha1 | a33461270cd801a0564e42794ea1200efb759e7a |
| Sha256 | 2458ab1e87a1d4f4d0cc84e02aad6a0c85d966e6c397766cb30e756419004779 |
| Sha384 | 388a9dfa1d7552aa6e5578b75dd8f8f1355c2bf8dc02722b618c23bc0b3f6cf224aa1e91712d87ad066d2cbc776478ce |
| Sha512 | b48222eb72f5a44f2e5c26c6fddbc2010f2fad5af2199c223090da834a0cfd940168056a78329bd6f6dc66dc6dd2611d03b0c8722c3a8c81cafb2d51b1e87a5d |
| SSDeep | 12288:dDSib5QzmvbRe5uBIR3SXgFHjF6wqELGdeBWdZ15ZKmtUAG7LAHW4SpUdA/RLSMl:m |
| TLSH | 8B5510523651FD7D029693B16E1646F0A46ACA80CEDF8556F24DCE8CB14EC863AF93C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.