Malicious
Malicious

612462df7b8bb698c61b84d228123cb8

PowerShell
MD5: 612462df7b8bb698c61b84d228123cb8
Size: 1.33 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 612462df7b8bb698c61b84d228123cb8
Sha1 6da19ddbbd4c3ee6869b54a18fc3b311866d6a42
Sha256 3d995f67024ab5280cff8f7dc1e67048ab9722810d21d3ecba1fe7e2b80b4e37
Sha384 6720ac7da11958a4334be0877bbc9e62211556e3c8bd03d8ba49b86a3b7c69834ddf282c6e34d5704516ed9f734535d9
Sha512 dd4a2b4dae9b4a170a4871bcc94b8b510de8fd57405a0c44f41778c746daed5367756b059f538426850eb349a9f02f79aa715d9345c455df30236b461d19e80f
SSDeep 12288:JV37BkebfObJvkFwnFVQk2FPZzDNQy+IvbxSz1muvqqpL9w/Oc1SDFgv5Vt5RlbK:EcZm
TLSH 6F5522523651FD7D029693B16E1646F0A46ACA40CEDF8596F24DCE8CB14EC863AF93C3
612462df7b8bb698c61b84d228123cb8
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
612462df7b8bb698c61b84d228123cb8
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙