Malicious
Malicious

542a0c34d4bf2ca6630a14d899a596c2

PowerShell
MD5: 542a0c34d4bf2ca6630a14d899a596c2
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 542a0c34d4bf2ca6630a14d899a596c2
Sha1 a33461270cd801a0564e42794ea1200efb759e7a
Sha256 2458ab1e87a1d4f4d0cc84e02aad6a0c85d966e6c397766cb30e756419004779
Sha384 388a9dfa1d7552aa6e5578b75dd8f8f1355c2bf8dc02722b618c23bc0b3f6cf224aa1e91712d87ad066d2cbc776478ce
Sha512 b48222eb72f5a44f2e5c26c6fddbc2010f2fad5af2199c223090da834a0cfd940168056a78329bd6f6dc66dc6dd2611d03b0c8722c3a8c81cafb2d51b1e87a5d
SSDeep 12288:dDSib5QzmvbRe5uBIR3SXgFHjF6wqELGdeBWdZ15ZKmtUAG7LAHW4SpUdA/RLSMl:m
TLSH 8B5510523651FD7D029693B16E1646F0A46ACA80CEDF8556F24DCE8CB14EC863AF93C3
542a0c34d4bf2ca6630a14d899a596c2
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
542a0c34d4bf2ca6630a14d899a596c2
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
542a0c34d4bf2ca6630a14d899a596c2
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙