Malicious
Malicious

6b6f4b3c73018240db656a102e821f45

PowerShell
MD5: 6b6f4b3c73018240db656a102e821f45
Size: 1.4 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6b6f4b3c73018240db656a102e821f45
Sha1 1b0cc93b725c907bd75cb342c55401cf60870116
Sha256 af87f7f4cdf75719fd9167b36a5f6ee0f3697b682fddcecf26a63d69fa3dc807
Sha384 989a1b2109b30442d4cb2cf9543d662b0659879d43758918ba6b67cd4daa5423ea5798fb0078b7793c5d7268cf9209e0
Sha512 265de37d8022d79ed33192374665e8930d3ac647e6d1077751551832662f63766892ffe64cd76ab8e6526614981d8a9d824456253a507dcaa8f110f2192fadf6
SSDeep 12288:Zs4edUv5GlqiJ0ZeMia6WgQkJrd1JRqzXJJeQ1adVJYy2+EhjAWx+1h/eMHU2uDj:J
TLSH 8F5511523651F97D029793B57E1646F0A46ACA40CEDF8556F24DCE8CA14EC823AFA3C3
6b6f4b3c73018240db656a102e821f45
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
6b6f4b3c73018240db656a102e821f45
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙