Malicious
Malicious

656f81e9c7baeb3f367c0dc91c4e9822

Share on LinkedIn
Print
PowerShell
MD5: 656f81e9c7baeb3f367c0dc91c4e9822
Size: 1.61 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 656f81e9c7baeb3f367c0dc91c4e9822
Sha1 377b1d1a3866aa9d548367472fa42a5908ee7538
Sha256 8c22c86461ce15d60338e6050de479d9d65234308156ae9cfdc6f5a1c9d5ce7d
Sha384 9492e3c95ed56ae51585a8686cc03c6f878b6d6278311b2e5b5b5f5d011d4e2976be019590e7b6ab6cc43eeafb7917a7
Sha512 b2819b122a45af3a16a4f45a7e3fccc83dc7e22b326c613a7cc63742f571d819bf65888b524b31653ccfaea8b20e78ba028de8668aaabe4b820f118df02c7476
SSDeep 12288:z5XExogw0bAiC2ig7BEnVqccxwJGAZ9sLkAtspiL9j9tJeDCu04MJ4W65LuusubJ:D
TLSH A775F0523551FD7D029693B16E1646F0A86ACA40CFDF8556F24DCE88B14EC863AFA3C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙