Malicious
612462df7b8bb698c61b84d228123cb8
PowerShell
MD5: 612462df7b8bb698c61b84d228123cb8
Size: 1.33 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 612462df7b8bb698c61b84d228123cb8 |
| Sha1 | 6da19ddbbd4c3ee6869b54a18fc3b311866d6a42 |
| Sha256 | 3d995f67024ab5280cff8f7dc1e67048ab9722810d21d3ecba1fe7e2b80b4e37 |
| Sha384 | 6720ac7da11958a4334be0877bbc9e62211556e3c8bd03d8ba49b86a3b7c69834ddf282c6e34d5704516ed9f734535d9 |
| Sha512 | dd4a2b4dae9b4a170a4871bcc94b8b510de8fd57405a0c44f41778c746daed5367756b059f538426850eb349a9f02f79aa715d9345c455df30236b461d19e80f |
| SSDeep | 12288:JV37BkebfObJvkFwnFVQk2FPZzDNQy+IvbxSz1muvqqpL9w/Oc1SDFgv5Vt5RlbK:EcZm |
| TLSH | 6F5522523651FD7D029693B16E1646F0A46ACA40CEDF8596F24DCE8CB14EC863AF93C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
612462df7b8bb698c61b84d228123cb8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.