Malicious
Malicious

656f81e9c7baeb3f367c0dc91c4e9822

PowerShell
MD5: 656f81e9c7baeb3f367c0dc91c4e9822
Size: 1.61 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 656f81e9c7baeb3f367c0dc91c4e9822
Sha1 377b1d1a3866aa9d548367472fa42a5908ee7538
Sha256 8c22c86461ce15d60338e6050de479d9d65234308156ae9cfdc6f5a1c9d5ce7d
Sha384 9492e3c95ed56ae51585a8686cc03c6f878b6d6278311b2e5b5b5f5d011d4e2976be019590e7b6ab6cc43eeafb7917a7
Sha512 b2819b122a45af3a16a4f45a7e3fccc83dc7e22b326c613a7cc63742f571d819bf65888b524b31653ccfaea8b20e78ba028de8668aaabe4b820f118df02c7476
SSDeep 12288:z5XExogw0bAiC2ig7BEnVqccxwJGAZ9sLkAtspiL9j9tJeDCu04MJ4W65LuusubJ:D
TLSH A775F0523551FD7D029693B16E1646F0A86ACA40CFDF8556F24DCE88B14EC863AFA3C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822 › [PowerShell Command]
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822 › [PowerShell Command]
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
656f81e9c7baeb3f367c0dc91c4e9822 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙