Malicious
581597a68b77c2a2818e36ccde029025
PowerShell
MD5: 581597a68b77c2a2818e36ccde029025
Size: 12.69 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 581597a68b77c2a2818e36ccde029025 |
| Sha1 | 89ca0a48db1b018f6ac4b8c9d9a8c10a565b6c6c |
| Sha256 | 51dbb63665de509b8c6ef9bf0c8e5dfb35ed22cfe5c5905c90ff343cc13fa91a |
| Sha384 | 92d00a315494eaa711339e141dbd3533a5d5493867f9094ea96f3be2c015794575717be76430c1550c338b4a1bf39c76 |
| Sha512 | e261e7c11b660d2c86f72a7eb87a5a655a6a76d4ab7b79ada86699fed2c75c138387e3af9ce567c5de29552edfe5d5d2c7a547a5adee0fd22b8a1add3f8bf7ee |
| SSDeep | 384:Rj96direJrr6XCXdbSbJ1J8DFtyK8lZ16Bw0c:RjUireEyHDFN8l6yr |
| TLSH | F3426CCC2881D0525B22432E164FEE4889D181E37930F44EF84EDF95EB94702E9FA4AF |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.007>scr:js~T1027~T1059.001~T1059.007~T1105
Shape
scr:ps1>scr:js
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
581597a68b77c2a2818e36ccde029025 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.