Malicious
Malicious

581597a68b77c2a2818e36ccde029025

PowerShell
MD5: 581597a68b77c2a2818e36ccde029025
Size: 12.69 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 581597a68b77c2a2818e36ccde029025
Sha1 89ca0a48db1b018f6ac4b8c9d9a8c10a565b6c6c
Sha256 51dbb63665de509b8c6ef9bf0c8e5dfb35ed22cfe5c5905c90ff343cc13fa91a
Sha384 92d00a315494eaa711339e141dbd3533a5d5493867f9094ea96f3be2c015794575717be76430c1550c338b4a1bf39c76
Sha512 e261e7c11b660d2c86f72a7eb87a5a655a6a76d4ab7b79ada86699fed2c75c138387e3af9ce567c5de29552edfe5d5d2c7a547a5adee0fd22b8a1add3f8bf7ee
SSDeep 384:Rj96direJrr6XCXdbSbJ1J8DFtyK8lZ16Bw0c:RjUireEyHDFN8l6yr
TLSH F3426CCC2881D0525B22432E164FEE4889D181E37930F44EF84EDF95EB94702E9FA4AF
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.007>scr:js~T1027~T1059.001~T1059.007~T1105
Shape scr:ps1>scr:js
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙