Malicious
Malicious

68fcac61f874902b0c8921ad6c2cd013

PowerShell
MD5: 68fcac61f874902b0c8921ad6c2cd013
Size: 1.35 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 68fcac61f874902b0c8921ad6c2cd013
Sha1 b1b0d0d985743688ba58bb7863fb516ceb6ca25e
Sha256 f4f6feb4153d901d89fc11921696346d40e2326b8162434f1816f595090582bd
Sha384 987838423a98b9476c4e4d2f07d0afeae5e012b9baf2f811dd6bc99f44a35c7c83265d57dd3310f5886f8157884bbec1
Sha512 82a2833a800416d044cc8e9293fd4bd58e5f90e07eb1c44edd81f2ceee3a5dc4f561a1335cfd3f96c192b01b968b0e8dabf2a481626f14ad6c25ab05f2bccff2
SSDeep 12288:Y5IOCTUT56I5LyVblDMU+7uKEehYBwklZkALpWm30GYpL1XgLAIPlJO+aodJ1l6X:E
TLSH F25512523A51FD7D029693B17E1646F0A86ACA40CEDF8556F24DCE88B14DC863AF93C3
68fcac61f874902b0c8921ad6c2cd013
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
68fcac61f874902b0c8921ad6c2cd013
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
68fcac61f874902b0c8921ad6c2cd013 › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
68fcac61f874902b0c8921ad6c2cd013
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
68fcac61f874902b0c8921ad6c2cd013
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙